PT-2026-33533 · Churchcrm · Churchcrm
Published
2026-04-17
·
Updated
2026-04-18
·
CVE-2026-40485
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 7.2.0
Description
The public API login endpoint '/api/public/user/login' returns different HTTP response codes depending on whether a username exists: 404 for non-existent users and 401 for valid users with incorrect passwords. An unauthenticated attacker can use this behavior to enumerate valid usernames, as there is no rate limiting or account lockout mechanism to prevent the process.
Recommendations
Update to version 7.2.0.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm