Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 19 Oct 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ChurchCRM setup.php deserialization | |
Weaknesses | CWE-20 CWE-502 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-10-19T07:32:05.836Z
Reserved: 2025-10-18T12:54:26.566Z
Link: CVE-2025-11938

No data.

Status : Received
Published: 2025-10-19T08:15:32.760
Modified: 2025-10-19T08:15:32.760
Link: CVE-2025-11938

No data.

No data.