Link Redirection Flaw in ChurchCRM Affects User Security
CVE-2026-35578
5.3MEDIUM
What is CVE-2026-35578?
ChurchCRM, an open-source church management system, has a security flaw that allows attacker-controlled URLs to be used in user redirection. If an authenticated user clicks the 'Cancel' button on certain pages, they can be redirected to any attacker-specified URL. This is particularly concerning as it may expose users to phishing or malicious sites. The vulnerability has been addressed in version 7.0.0, highlighting the importance of keeping software up to date.
Affected Version(s)
CRM < 7.0.0
