CVE-2025-62521 is a critical pre-authentication remote code execution vulnerability affecting ChurchCRM versions prior to 5.21.0. This flaw allows unauthenticated attackers to inject arbitrary PHP code during the initial setup wizard, leading to complete server compromise due to unsanitized user input being written to a configuration file. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.62788, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in high impact to confidentiality, integrity, and availability. An exploit module for Metasploit is publicly available, and the vulnerability has garnered significant community discussion and media coverage, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.21.0CPE matchmatch criteria | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.