Incorrect authorization in ChurchCRM - #VU152742
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose events from other calendars, including private calendars.
The vulnerability exists due to improper authorization in PublicCalendarMiddleware::getEvents() when handling public calendar requests containing a start parameter. A remote user can send a request containing a start parameter to disclose events from other calendars, including private calendars.
The external calendar API must be enabled, and a public calendar access token must be available.