Improper access control in ChurchCRM - #VU129693

 

Improper access control in ChurchCRM - #VU129693

Published: May 5, 2026


Vulnerability identifier: #VU129693
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in src/kiosk/routes/device.php when handling requests to the activeClassMember photo endpoint. A remote attacker can request photos for arbitrary PersonId values to disclose sensitive information.

The endpoint can be abused by iterating PersonId values.


Affected software

ChurchCRM

Remediation

Install security update from vendor's website.

ChurchCRM - update to 7.1.0

External References

Related Security Bulletins