{"id":"CVE-2025-68109","title":"ChurchCRM is an open-source church management system","summary":"ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file …","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-78","CWE-434","CWE-494","CWE-552","CWE-915"],"vendor":"churchcrm","product":"churchcrm","affected":["churchcrm < 6.5.3"],"patched":["churchcrm 6.5.3"],"published":"2025-12-17","updated":"2026-10-01","sourceUpdated":"2026-10-01T16:10:00.257","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-68109","references":[{"url":"https://github.com/ChurchCRM/CRM/security/advisories/GHSA-pqm7-g8px-9r77","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.01547,"epssPercentile":0.74125,"exploits":{"metasploit":["exploit/multi/http/churchcrm_db_restore_rce"],"checkedAt":"2026-10-02T18:58:17.899Z"},"exploitAvailable":true,"ingestedAt":"2026-10-01T18:55:42.306Z","slug":"CVE-2025-68109","body":"## Overview\n\nChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct access to it. Once accessed, the uploaded web shell allows remote code execution (RCE) on the server. Version 6.5.3 fixes the issue.\n\n## Affected\n\n- `churchcrm < 6.5.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `churchcrm 6.5.3`","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}