#VU125714 Observable Response Discrepancy in ChurchCRM - CVE-2025-67874
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to observable response discrepancy in HTTP responses when processing user-supplied passwords. A remote privileged user can submit a password and receive it back in plaintext in the response to disclose sensitive information.
This can occur in workflows such as registration, password change or reset, and login error handling.