← All Advisories

ChurchCRM Before 6.5.3 Backup Restore Functionality Allows Authenticated Administrators to Upload Files to Arbitrary Paths via Path Traversal, Enabling Remote Code Execution

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-35573

Key Details

CVECVE-2026-35573
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productschurchcrm churchcrm
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
churchcrmchurchcrm
SubsystemsGeneral OT
SectorsMultiple

What to Know

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile['name'] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/html/tmp_attach/ChurchCRMBackups/. This vulnerability is fixed in 6.5.3. (NVD)

What to Do

Monitor churchcrm's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-35573
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-35573