CVE-2025-62521
CWE-94Published: December 17, 2025· Updated: Jun 17, 2026
Official Description
ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The vulnerability exists in `setup/routes/setup.php` where user input from the setup form is directly concatenated into a PHP configuration template without any validation or sanitization. Any parameter in the setup form can be used to inject PHP code that gets written to `Include/Config.php`, which is then executed on every page load. This is more severe than typical authenticated RCE vulnerabilities because it requires no credentials and affects the installation process that administrators must complete. Version 5.21.0 patches the issue.
Risk Analysis
ChurchCRM contains a pre-authentication remote code execution vulnerability in its setup wizard. Attackers can inject arbitrary PHP code during installation, leading to full server compromise.
No public exploit is known, and it is not in KEV. The vulnerability is remotely exploitable with low complexity.
Upgrade to ChurchCRM version 5.21.0 or later to fix the input validation flaw in the setup process.
Technical Analysis
CVE-2025-62521 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 9.8.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
Official Patches & Advisories
All References (1)
Quick Facts
Related CVEs (CWE-94)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2025-62521 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts