Server-Side Request Forgery (SSRF) in ChurchCRM - #VU129708
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to server-side request forgery in the referrer handling logic when processing a GET request to the Dashboard with an external referrer. A remote user can supply a crafted referrer value to cause a denial of service.
Exploitation requires the attacker to be logged in.