← Πίσω στην αναζήτηση CVE

CVE-2026-35573

ChurchCRM

Περιγραφή

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM-s backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile[-name-] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/html/tmp_attach/ChurchCRMBackups/. This vulnerability is fixed in 6.5.3.

CVSS 9.1EPSS 0.765%Κίνδυνος 0.97
Προβολή πηγής
Δημοσίευση
2026-04-07 18:16:41
Επηρεαζόμενες εκδόσεις
<6.5.3
Τύπος
Package
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H