CVE-2025-66397
8.3ChurchCRM · ChurchCRM
ChurchCRM versions prior to 6.5.3 suffer from broken access control in the Kiosk Manager feature, allowing authenticated users to perform unauthorized administrative actions.
Executive summary
A broken access control vulnerability in ChurchCRM allows authenticated users to perform unauthorized administrative actions, posing a significant risk to system integrity.
Vulnerability
The vulnerability exists due to improper access control within the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions. Any authenticated user can trigger these functions to manipulate kiosk registrations or perform management actions without the required privileges.
Business impact
The ability for standard users to manipulate kiosk registration and management functions grants unauthorized control over critical operational features. Given the CVSS score of 8.3, this flaw represents a high risk, as it could lead to the unauthorized acceptance of untrusted kiosks, potential data exposure, or the disruption of church management operations.
Remediation
Immediate Action: Update ChurchCRM to version 6.5.3 or later to apply the necessary access control checks.
Proactive Monitoring: Review application access logs for unusual activity associated with Kiosk Manager functions or unauthorized attempts to modify kiosk settings.
Compensating Controls: Restrict access to the application to trusted internal networks and ensure that user roles are strictly defined to limit the potential impact of compromised or malicious accounts.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
This vulnerability presents a high risk to administrative integrity within the ChurchCRM platform. Administrators must prioritize the update to version 6.5.3 immediately to remediate the access control flaw and prevent potential unauthorized manipulation of kiosk management features.