Information disclosure in ChurchCRM - CVE-2025-68110

 

Information disclosure in ChurchCRM - CVE-2025-68110

Published: April 9, 2026


Vulnerability identifier: #VU125681
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68110
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in StatementWrapper.php when handling database errors. A remote user can trigger an uncaught database exception to disclose sensitive information.

Exposed error messages may include the database host, IP address, username, and password.


Affected software

ChurchCRM

How to mitigate CVE-2025-68110

Install security update from vendor's website.

ChurchCRM - update to 6.5.3

External References

Related Security Bulletins