Remote Code Execution Flaw in Church Management System by ChurchCRM
CVE-2026-42288
10CRITICAL
What is CVE-2026-42288?
ChurchCRM, an open-source church management system, contains a pre-authentication remote code execution vulnerability in its setup wizard due to unsanitized DB_PASSWORD. This flaw allows attackers to exploit the system and execute arbitrary code without prior authentication. The vulnerability is particularly concerning as it remains fully exploitable in versions prior to 7.3.2. A fix has been implemented in version 7.3.2, addressing this security issue. Users are recommended to upgrade to the latest version to mitigate potential risks.
Affected Version(s)
CRM < 7.3.2
