CVE-2026-35575

8.0

ChurchCRM · CRM

A stored cross-site scripting vulnerability in ChurchCRM prior to version 6.5.3 allows authenticated users to execute malicious scripts in an administrator session, potentially leading to account takeover.

Executive summary

A high-severity stored cross-site scripting vulnerability in ChurchCRM allows authenticated attackers to execute arbitrary JavaScript, posing a risk of full administrative account takeover.

Vulnerability

This vulnerability is a stored cross-site scripting (XSS) flaw located in the admin panel group-creation feature. It requires an authenticated user with group-creation privileges to inject malicious scripts, which execute when an administrator interacts with the compromised page.

Business impact

The vulnerability carries a CVSS score of 8.0, reflecting its significant potential for impact. Successful exploitation permits attackers to hijack administrative sessions, granting them unauthorized access to sensitive church management data, member information, and system configuration, which could result in severe data breaches and loss of system integrity.

Remediation

Immediate Action: Upgrade ChurchCRM to version 6.5.3 or later to apply the security fix provided by the vendor.

Proactive Monitoring: Monitor server logs for suspicious activity originating from authenticated user accounts, specifically focusing on the group-creation module.

Compensating Controls: Implement a Content Security Policy (CSP) to restrict the execution of unauthorized scripts and utilize a Web Application Firewall (WAF) to filter malicious input patterns associated with XSS attacks.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for complete administrative account takeover, this vulnerability poses a critical risk to the confidentiality and integrity of your organization. IT administrators must prioritize updating ChurchCRM to version 6.5.3 immediately to eliminate the underlying injection flaw and prevent session hijacking attempts.

More ChurchCRM CVEs

Sources