CVE-2025-66397 HIGH

CVE-2025-66397: ChurchCRM's Kiosk Manager Functions are vulnerable to Broken Access Control

Vendor Churchcrm
Product CRM
Weakness CWE-284
Published December 17, 2025
Last update December 17, 2025

CVSS base score

8.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

What the vulnerability does

01Description

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from broken access control, allowing any authenticated user to allow and accept kiosk registrations, and perform other Kiosk Manager actions such as reload and identify. Version 6.5.3 fixes the issue.

Key dates

02Disclosure timeline

December 17, 2025 CVE published
December 17, 2025 Record updated