Vulnerability Description
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token validation. An unauthenticated attacker can craft a malicious HTML page that, when visited by an authenticated administrator, silently elevates any low-privilege user to full administrator or creates a new admin backdoor account without the victim's knowledge This vulnerability is fixed in 7.3.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/ChurchCRM/CRM/security/advisories/GHSA-3xq9-c86x-cwpp
- https://github.com/ChurchCRM/CRM/security/advisories/GHSA-3xq9-c86x-cwpp
FAQ
What is CVE-2026-42289?
CVE-2026-42289 is a vulnerability with a CVSS score of 8.8 (HIGH). ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token valida...
How severe is CVE-2026-42289?
CVE-2026-42289 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42289?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.