ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify the impact of other vulnerabilities (e.g., XSS, IDOR, session fixation), enabling attackers to harvest other users’ passwords. Version 6.5.0 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/ChurchCRM/CRM/commit/2d6cf7aed9af1b9b47e125d1a2266f8e2a88f3fd | Patch |
| https://github.com/ChurchCRM/CRM/security/advisories/GHSA-p98h-5xcj-5c6x | Exploit Vendor Advisory |
Configurations
History
17 Dec 2025, 14:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ChurchCRM/CRM/commit/2d6cf7aed9af1b9b47e125d1a2266f8e2a88f3fd - Patch | |
| References | () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-p98h-5xcj-5c6x - Exploit, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Churchcrm churchcrm
Churchcrm |
|
| CPE | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* |
16 Dec 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-16 01:15
Updated : 2025-12-17 14:14
NVD link : CVE-2025-67874
Mitre link : CVE-2025-67874
CVE.ORG link : CVE-2025-67874
JSON object : View
Products Affected
churchcrm
- churchcrm
CWE
CWE-204
Observable Response Discrepancy
