ZeroHour

CVE-2025-66397

PoC
CVSS 3.1
8.3 high
EPSS
<1%p22
Published
()
Modified
Description

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from broken access control, allowing any authenticated user to allow and accept kiosk registrations, and perform other Kiosk Manager actions such as reload and identify. Version 6.5.3 fixes the issue.

Vendors
churchcrm
Products
churchcrm
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

In the news

No ingested article mentions this CVE yet.