Link Redirection Flaw in ChurchCRM Affects User Security
CVE-2026-35578

5.3MEDIUM

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35578?

ChurchCRM, an open-source church management system, has a security flaw that allows attacker-controlled URLs to be used in user redirection. If an authenticated user clicks the 'Cancel' button on certain pages, they can be redirected to any attacker-specified URL. This is particularly concerning as it may expose users to phishing or malicious sites. The vulnerability has been addressed in version 7.0.0, highlighting the importance of keeping software up to date.

Affected Version(s)

CRM < 7.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.