Authorization bypass through user-controlled key in ChurchCRM - #VU139934

 

Authorization bypass through user-controlled key in ChurchCRM - #VU139934

Published: July 28, 2026


Vulnerability identifier: #VU139934
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the web-accessible /Images/Person/ and /Images/Family/ directories when requesting predictable static file paths for uploaded photos. A remote attacker can request crafted direct file paths to disclose sensitive information.

Uploaded person and family photos are intended to be retrieved through authenticated API endpoints, but numeric entity IDs are used as filenames for directly served PNG files.


Affected software

ChurchCRM

Remediation

Install security update from vendor's website.

ChurchCRM - update to 7.4.3

External References

Related Security Bulletins