Open redirect in ChurchCRM - CVE-2026-35578

 

Open redirect in ChurchCRM - CVE-2026-35578

Published: April 9, 2026


Vulnerability identifier: #VU125692
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35578
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect users to an arbitrary external website.

The vulnerability exists due to url redirection to untrusted site in DonatedItemEditor.php when handling the user-supplied linkBack URL parameter. A remote user can craft a malicious link to redirect users to an arbitrary external website.

User interaction is required to click the Cancel button, and the victim must be authenticated to the application.


Affected software

ChurchCRM

How to mitigate CVE-2026-35578

Install security update from vendor's website.

ChurchCRM - update to 7.0.0

External References

Related Security Bulletins