PT-2026-30940 · Churchcrm · Churchcrm

Uartu0

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35573

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a path traversal flaw in its backup restore functionality. Authenticated administrators can exploit this to upload arbitrary files and potentially achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability resides in the RestoreJob.php file within the src/ChurchCRM/Backup/RestoreJob.php path. The $rawUploadedFile['name'] parameter is user-controlled, enabling the upload of files with arbitrary names to the /var/www/html/tmp attach/ChurchCRMBackups/ directory.
Recommendations Update ChurchCRM to version 6.5.3 or later.

Exploit

Fix

Unrestricted File Upload

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-35573

Affected Products

Churchcrm