Path Traversal Vulnerability in ChurchCRM Management System
CVE-2026-35573

9.1CRITICAL

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35573?

ChurchCRM, an open-source church management system, contains a path traversal vulnerability in its backup restore feature. This issue allows authenticated administrators to upload files with arbitrary names, potentially leading to remote code execution by overwriting sensitive Apache .htaccess configuration files. The vulnerability is found in the RestoreJob.php file and was present in versions prior to 6.5.3. Users are advised to update their systems to mitigate this risk.

Affected Version(s)

CRM < 6.5.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.