Path Traversal Vulnerability in ChurchCRM Management System
CVE-2026-35573
9.1CRITICAL
What is CVE-2026-35573?
ChurchCRM, an open-source church management system, contains a path traversal vulnerability in its backup restore feature. This issue allows authenticated administrators to upload files with arbitrary names, potentially leading to remote code execution by overwriting sensitive Apache .htaccess configuration files. The vulnerability is found in the RestoreJob.php file and was present in versions prior to 6.5.3. Users are advised to update their systems to mitigate this risk.
Affected Version(s)
CRM < 6.5.3
