CRITICAL🇵🇱 Wersja polska

CVE-2026-35573

CVSS 9.1v3.1pub. 2026-04-07upd. 2026-04-10

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile['name'] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/html/tmp_attach/ChurchCRMBackups/. This vulnerability is fixed in 6.5.3.

🤖 AI Analysis
How it works

The vulnerability is located in the file src/ChurchCRM/Backup/RestoreJob.php, where the parameter $rawUploadedFile['name'] is fully controlled by the user. Lack of proper file name validation allows an attacker to upload a file with any path to the /var/www/html/tmp_attach/ChurchCRMBackups/ directory. Through path traversal sequences, it is possible to overwrite the Apache .htaccess file, which leads to server configuration modification and ultimately to remote code execution.

Impact

An attacker with administrator privileges can gain full control of the server through remote code execution (RCE), and can also compromise the confidentiality, integrity, and availability of the system.

Mitigation & patch

ChurchCRM should be updated to version 6.5.3 or later, in which the vulnerability has been fixed. According to manufacturer references, it is available directly in the project's GitHub repository.

Who is affected

ChurchCRM in all versions prior to 6.5.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Churchcrm

    APP
    Churchcrm
    < 6.5.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2026-39342CRITICAL9.4PL ✓same product

SQL Injection w ChurchCRM przez parametr searchwhat (QueryView.php)

CVE-2026-39339CRITICAL9.1PL ✓same product

ChurchCRM — krytyczny auth bypass w API middleware

CVE-2026-39337CRITICAL10.0PL ✓same product

ChurchCRM: pre-auth RCE przez wstrzyknięcie kodu PHP w kreatorze instalacji

CVE-2025-68110CRITICAL9.9PL ✓same product

ChurchCRM: ujawnienie danych logowania do bazy danych w komunikacie błędu

CVE-2025-67876CRITICAL9.3PL ✓same product

Stored XSS w ChurchCRM — przejęcie konta przez nazwy ról grup