ChurchCRM ଯେପର୍ଯ୍ୟନ୍ତ 5.18.0 setup/routes/setup.php DB_PASSWORD/ROOT_PATH/URL ବିସ୍ତାରିତ ଅଧିକାର

Dogoggorri kan akka ଜଟିଳ jedhamuun ramadame ChurchCRM ଯେପର୍ଯ୍ୟନ୍ତ 5.18.0 keessatti argameera. Miidhaan irra gahe is hojii hin beekamne faayilii setup/routes/setup.php keessa. Dhugumatti jijjiirraa irratti raawwatame DB_PASSWORD/ROOT_PATH/URL gara ବିସ୍ତାରିତ ଅଧିକାର geessa. Waliigalteewwan CWE fayyadamuun rakkoo ibsuun gara CWE-502 si geessa. Beekumsi kun yeroo 10/18/2025 ifoomsifameera. Odeeffannoon kun buufachuuf github.com irratti dhiyaateera. Dogoggorri kun maqaa CVE-2025-11938 jedhuun tajaajilama. Weerara fageenya irraa jalqabuun ni danda'ama. Odeeffannoon teeknikaa ni argama. Akka dabalataan, meeshaa balaa kana fayyadamuuf argama. Qorannoo miidhaa (exploit) beeksifamee jira, namoonni itti fayyadamuu danda'u. Yeroo ammaa, gatii exploit might be approx. USD $0-$5k beekamuu danda'a. ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee murtaa’eera. Exploit kana github.com irraa buufachuu ni dandeessa. Waggaa 0-day ta'ee, gatiin isaa daldala dhoksaa keessatti $0-$5k jedhamee tilmaamame. Once again VulDB remains the best source for vulnerability data.

5 ଆଡାପ୍ଟେସନ୍ · 103 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
10/18/2025 02:59 PM
ଅଦ୍ୟତନ 1/4
10/19/2025 10:38 AM
ଅଦ୍ୟତନ 2/4
10/19/2025 12:42 PM
ଅଦ୍ୟତନ 3/4
10/20/2025 08:42 PM
ଅଦ୍ୟତନ 4/4
10/27/2025 03:31 PM
software_nameChurchCRMChurchCRMChurchCRMChurchCRMChurchCRM
software_version<=5.18.0<=5.18.0<=5.18.0<=5.18.0<=5.18.0
software_filesetup/routes/setup.phpsetup/routes/setup.phpsetup/routes/setup.phpsetup/routes/setup.phpsetup/routes/setup.php
software_argumentDB_PASSWORD/ROOT_PATH/URLDB_PASSWORD/ROOT_PATH/URLDB_PASSWORD/ROOT_PATH/URLDB_PASSWORD/ROOT_PATH/URLDB_PASSWORD/ROOT_PATH/URL
vulnerability_cweCWE-502 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-502 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-502 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-502 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-502 (ବିସ୍ତାରିତ ଅଧିକାର)
vulnerability_risk22222
cvss3_vuldb_avNNNNN
cvss3_vuldb_acHHHHH
cvss3_vuldb_prNNNNN
cvss3_vuldb_uiNNNNN
cvss3_vuldb_sUUUUU
cvss3_vuldb_cLLLLL
cvss3_vuldb_iLLLLL
cvss3_vuldb_aLLLLL
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
advisory_urlhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.md
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.mdhttps://github.com/uartu0/advisories/blob/main/churchcrm-setup-rce-2025.md
source_cveCVE-2025-11938CVE-2025-11938CVE-2025-11938CVE-2025-11938CVE-2025-11938
cna_responsibleVulDBVulDBVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
cvss2_vuldb_avNNNNN
cvss2_vuldb_acHHHHH
cvss2_vuldb_auNNNNN
cvss2_vuldb_ciPPPPP
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiPPPPP
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss4_vuldb_avNNNNN
cvss4_vuldb_acHHHHH
cvss4_vuldb_prNNNNN
cvss4_vuldb_uiNNNNN
cvss4_vuldb_vcLLLLL
cvss4_vuldb_viLLLLL
cvss4_vuldb_vaLLLLL
cvss4_vuldb_ePPPPP
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_rlXXXXX
cvss4_vuldb_atNNNNN
cvss4_vuldb_scNNNNN
cvss4_vuldb_siNNNNN
cvss4_vuldb_saNNNNN
cvss2_vuldb_basescore5.15.15.15.15.1
cvss2_vuldb_tempscore4.44.44.44.44.4
cvss3_vuldb_basescore5.65.65.65.65.6
cvss3_vuldb_tempscore5.15.15.15.15.1
cvss3_meta_basescore5.65.65.65.66.4
cvss3_meta_tempscore5.15.15.35.36.3
cvss4_vuldb_bscore6.36.36.36.36.3
cvss4_vuldb_btscore2.92.92.92.92.9
advisory_date1760738400 (10/18/2025)1760738400 (10/18/2025)1760738400 (10/18/2025)1760738400 (10/18/2025)1760738400 (10/18/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
euvd_idEUVD-2025-35002EUVD-2025-35002EUVD-2025-35002EUVD-2025-35002
cve_nvd_summaryA vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
cvss4_cna_avNNN
cvss4_cna_acHHH
cvss4_cna_atNNN
cvss4_cna_prNNN
cvss4_cna_uiNNN
cvss4_cna_vcLLL
cvss4_cna_viLLL
cvss4_cna_vaLLL
cvss4_cna_scNNN
cvss4_cna_siNNN
cvss4_cna_saNNN
cvss4_cna_bscore6.36.36.3
cvss3_cna_avNNN
cvss3_cna_acHHH
cvss3_cna_prNNN
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iLLL
cvss3_cna_aLLL
cvss3_cna_basescore5.65.65.6
cvss2_cna_avNNN
cvss2_cna_acHHH
cvss2_cna_auNNN
cvss2_cna_ciPPP
cvss2_cna_iiPPP
cvss2_cna_aiPPP
cvss2_cna_basescore5.15.15.1
cnnvd_idCNNVD-202510-2557CNNVD-202510-2557
cnnvd_nameChurchCRM 代码问题漏洞ChurchCRM 代码问题漏洞
cnnvd_hazardlevel33
cnnvd_create2025-10-202025-10-20
cnnvd_publish2025-10-192025-10-19
cnnvd_update2025-10-202025-10-20
cvss3_nvd_avN
cvss3_nvd_acH
cvss3_nvd_prN
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iH
cvss3_nvd_aH
cvss3_nvd_basescore8.1

Want to stay up to date on a daily basis?

Enable the mail alert feature now!