Incorrect authorization in ChurchCRM - #VU142444
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to read and modify arbitrary person records.
The vulnerability exists due to improper access control in the person-properties API routes when handling requests for arbitrary personId values. A remote user can send crafted API requests to read and modify arbitrary person records.
The issue affects accounts with MenuOptions permission but without EditRecords permission, and enables reading, adding, updating, and removing custom property assignments on other users\' person records.