← Volver a CVEs
CVE-2026-40581
HIGH8.1
Descripcion
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a malicious page that, when visited by an authenticated administrator, silently triggers deletion of targeted family records including associated notes, pledges, persons, and property data without any user interaction. This issue has been fixed in version 7.2.0.
Detalles CVE
Puntuacion CVSS v3.18.1
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado4/18/2026
Ultima modificacion4/18/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-352CWE-862
Referencias
https://github.com/ChurchCRM/CRM/commit/39361628613af7682b813f3e62a412559616d674(security-advisories@github.com)
https://github.com/ChurchCRM/CRM/pull/8613(security-advisories@github.com)
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-6qxv-xw9j-77pj(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.