PT-2026-33525 · Churchcrm · Churchcrm
Published
2026-04-17
·
Updated
2026-04-18
·
CVE-2026-40480
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 7.2.0
Description
An issue exists in the API layer where the 'GET /api/person/{personId}' endpoint returns person records without performing object-level authorization checks. While the legacy PersonView.php page enforces restrictions via the
canEditPerson() function, the API fails to do so. This allows any authenticated user with EditSelf privileges to enumerate and read records of other members, leading to the disclosure of sensitive personally identifiable information (PII) such as names, addresses, phone numbers, and email addresses.Recommendations
Update to version 7.2.0.
Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm