CVE-2025-67875

ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticated user with specific mid-level permissions ("Edit Records" and "Manage Properties and Classifications") can inject a persistent Cross-Site Scripting (XSS) payload into an administrator's profile. The payload executes when the administrator views their own profile page, allowing the attacker to hijack the administrator's session, perform administrative actions, and achieve a full account takeover. This vulnerability is a combination of two separate flaws: an Insecure Direct Object Reference (IDOR) that allows any user to view any other user's profile, and a Broken Access Control vulnerability that allows a user with general edit permissions to modify any other user's record properties. Version 6.5.3 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

18 Dec 2025, 18:31

Type Values Removed Values Added
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
First Time Churchcrm churchcrm
Churchcrm
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-fcw7-mmfh-7vjm - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-fcw7-mmfh-7vjm - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

18 Dec 2025, 15:16

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-fcw7-mmfh-7vjm - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-fcw7-mmfh-7vjm -

17 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 22:16

Updated : 2025-12-18 18:31


NVD link : CVE-2025-67875

Mitre link : CVE-2025-67875

CVE.ORG link : CVE-2025-67875


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')