Deserialization Vulnerability in ChurchCRM Affects Remote Setup Code
CVE-2025-11938
Key Information:
Badges
What is CVE-2025-11938?
A deserialization vulnerability was identified in ChurchCRM versions up to 5.18.0, specifically in the file setup/routes/setup.php. This flaw allows an attacker to manipulate parameters such as DB_PASSWORD, ROOT_PATH, and URL, resulting in potential remote code execution. The complexity of successfully exploiting this vulnerability is high, and although the exploit has been publicized, details on its effective utilization are challenging. The vendor was notified of this issue, yet there has been no response regarding mitigation or acknowledgment of the vulnerabilities.
Affected Version(s)
ChurchCRM 5.0
ChurchCRM 5.1
ChurchCRM 5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved