CVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile['name'] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/html/tmp_attach/ChurchCRMBackups/. This vulnerability is fixed in 6.5.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

10 Apr 2026, 20:59

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-r6cr-mvr9-f6wx - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-r6cr-mvr9-f6wx - Exploit, Third Party Advisory
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
First Time Churchcrm churchcrm
Churchcrm

08 Apr 2026, 19:25

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-r6cr-mvr9-f6wx - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-r6cr-mvr9-f6wx -

07 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 18:16

Updated : 2026-04-10 20:59


NVD link : CVE-2026-35573

Mitre link : CVE-2026-35573

CVE.ORG link : CVE-2026-35573


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type