PT-2026-33525 · Churchcrm · Churchcrm

Published

2026-04-17

·

Updated

2026-04-18

·

CVE-2026-40480

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.2.0
Description An issue exists in the API layer where the 'GET /api/person/{personId}' endpoint returns person records without performing object-level authorization checks. While the legacy PersonView.php page enforces restrictions via the canEditPerson() function, the API fails to do so. This allows any authenticated user with EditSelf privileges to enumerate and read records of other members, leading to the disclosure of sensitive personally identifiable information (PII) such as names, addresses, phone numbers, and email addresses.
Recommendations Update to version 7.2.0.

Exploit

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-40480

Affected Products

Churchcrm