Cross-Site Navigation Vulnerability in ChurchCRM Affects User Data Integrity
CVE-2026-44548
8.1HIGH
What is CVE-2026-44548?
The vulnerability identified in ChurchCRM allows an attacker to leverage top-level cross-site GET navigation from a malicious page to gain unauthorized access to sensitive functions. This can lead to a logged-in user, possessing the appropriate rights, unknowingly deleting critical records, including related data and assignments. This represents a significant risk to data integrity and user trust, as actions are performed without the user's explicit consent. The issue has been addressed in version 7.3.2.
Affected Version(s)
CRM < 7.3.2
