Security Advisory

CVE-2026-35572

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-07 17:07:57
Last updated 2026-04-07 19:59:43
Assigner GitHub_M
State PUBLISHED

Description

ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (SSRF) by supplying a crafted URL in the Referer request header. The server subsequently makes an outbound request to the attacker-controlled domain, confirmed via OAST. This vulnerability is fixed in 6.5.3.