#VU125717 SQL injection in ChurchCRM - CVE-2025-67877
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in /src/CartToFamily.php when handling the PersonAddress POST parameter in the Add to Family feature. A remote user can send a specially crafted POST request to disclose sensitive information.
Exploitation requires the Add Records permission.