PT-2026-40459 · Churchcrm · Churchcrm

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-42289

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.3.2
Description ChurchCRM is an open-source church management system. The UserEditor.php file processes user account creation and permission updates using $ POST parameters without validating Cross-Site Request Forgery (CSRF) tokens. CSRF is a technique where an attacker tricks a victim into performing actions they did not intend to do. An unauthenticated attacker can use a malicious HTML page to silently elevate a low-privilege user to administrator status or create a new administrator backdoor account if an authenticated administrator visits the page.
Recommendations Update to version 7.3.2.

Exploit

Fix

LPE

Improper Privilege Management

CSRF

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-42289

Affected Products

Churchcrm