Missing Authorization in ChurchCRM - #VU152741
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to delete a church calendar.
The vulnerability exists due to missing authorization in the DELETE /api/calendars/{id} endpoint when handling authenticated DELETE requests. A remote user can send a DELETE request for a calendar identifier to delete a church calendar.
Deleting a shared calendar also removes its associated access token.