Back to Database
Status published
Critical
CVE-2025-68110
ChurchCRM discloses database information on error message
Vulnerability Description
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68110
Credits & Attribution
No credits recorded in the NVD database.
More from ChurchCRM
View All →CVE-2025-68401
ChurchCRM has Stored Cross-Site Scripting (XSS) vulnerability that leads to session theft and account takeover
Medium
6.2
CVE-2025-68400
ChurchCRM vulnerable to time-based blind SQL Injection in ConfirmReportEmail.php
Critical
9.3
CVE-2025-68399
ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php
Low
2
CVE-2025-68275
ChurchCRM vulnerable to Stored XSS - Group name > Person Listing
Critical
9.2
CVE-2025-68112
ChurchCRM has SQL injection in EditEventAttendees.php
Critical
9.6
Affected Vendor
ChurchCRM
View all reports →Affected Software
CRM
Vulnerable Versions:
< 6.5.3
Timeline
Official Publish:
December 17th, 2025
Last Modified:
December 18th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
MITRE ATT&CK TTPs
T1213
Data from Information Repositories
Collection
T1005
Data from Local System
Collection
T1552
Unsecured Credentials
Credential Access
T1041
Exfiltration Over C2 Channel
Exfiltration
T1592
Gather Victim Host Information
Reconnaissance
T1083
File and Directory Discovery
Discovery
T1212
Exploitation for Defense Evasion
Defense Evasion