PT-2026-40459 · Churchcrm · Churchcrm

CVE-2026-42289

·

Published

2026-05-12

·

Updated

2026-05-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.3.2
Description ChurchCRM is an open-source church management system. The UserEditor.php file processes user account creation and permission updates using $ POST parameters without validating Cross-Site Request Forgery (CSRF) tokens. CSRF is a technique where an attacker tricks a victim into performing actions they did not intend to do. An unauthenticated attacker can use a malicious HTML page to silently elevate a low-privilege user to administrator status or create a new administrator backdoor account if an authenticated administrator visits the page.
Recommendations Update to version 7.3.2.

Exploit

Fix

LPE

Improper Privilege Management

CSRF

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42289

Affected Products

Churchcrm