CVE-2025-66397

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from broken access control, allowing any authenticated user to allow and accept kiosk registrations, and perform other Kiosk Manager actions such as reload and identify. Version 6.5.3 fixes the issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

18 Dec 2025, 19:07

Type Values Removed Values Added
First Time Churchcrm churchcrm
Churchcrm
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-32vr-ch3p-wmr5 - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-32vr-ch3p-wmr5 - Exploit, Vendor Advisory

17 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 20:15

Updated : 2025-12-18 19:07


NVD link : CVE-2025-66397

Mitre link : CVE-2025-66397

CVE.ORG link : CVE-2025-66397


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-284

Improper Access Control