Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-68109

Опубликовано: 17 дек. 2025
Источник: nvd
CVSS3: 9.1
CVSS3: 7.2
EPSS Низкий

Описание

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct access to it. Once accessed, the uploaded web shell allows remote code execution (RCE) on the server. Version 6.5.3 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
Версия до 6.5.3 (исключая)

EPSS

Процентиль: 46%
0.00234
Низкий

9.1 Critical

CVSS3

7.2 High

CVSS3

Дефекты

CWE-78

EPSS

Процентиль: 46%
0.00234
Низкий

9.1 Critical

CVSS3

7.2 High

CVSS3

Дефекты

CWE-78