CVE 6.9 MEDIUM

ChurchCRM has plaintext password return in response_CVE-2025-67874

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify the impact of other vulnerabilities (e.g., XSS, IDOR, session fixation), enabling attackers to harvest other users’ passwords. Version 6.5.0 fixes the issue.

Basic Information

ID CVE-2025-67874
Source GitHub_M
Published Dec 16, 2025 at 00:44

Affected Product

Vendor ChurchCRM
Product CRM
Version < 6.5.0
Affected Versions ChurchCRM CRM < 6.5.0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.