CVE-2025-67874
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify the impact of other vulnerabilities (e.g., XSS, IDOR, session fixation), enabling attackers to harvest other users’ passwords.
Version 6.5.0 fixes the issue.
MEDIUM · CVSS 6.5
EPSS 0.00043
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0