ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from broken access control, allowing any authenticated user to allow and accept kiosk registrations, and perform other Kiosk Manager actions such as reload and identify. Version 6.5.3 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/ChurchCRM/CRM/security/advisories/GHSA-32vr-ch3p-wmr5 | Exploit Vendor Advisory |
Configurations
History
18 Dec 2025, 19:07
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Churchcrm churchcrm
Churchcrm |
|
| CPE | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
| References | () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-32vr-ch3p-wmr5 - Exploit, Vendor Advisory |
17 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 20:15
Updated : 2025-12-18 19:07
NVD link : CVE-2025-66397
Mitre link : CVE-2025-66397
CVE.ORG link : CVE-2025-66397
JSON object : View
Products Affected
churchcrm
- churchcrm
CWE
CWE-284
Improper Access Control
