Junglewise Threat Intelligence

CVE-2026-39940: ChurchCRM open redirect via linkBack parameter

CVE-2026-39940 · Severity: info · CVSS 5.3 · Published 2026-04-13

Technologies: ChurchCRM. Vendors: ChurchCRM.

Executive brief

ChurchCRM, an open-source church management system, is vulnerable to a security flaw that allows attackers to redirect users to malicious websites. By sending a specially crafted link to a logged-in staff member or administrator, an attacker can trick them into visiting an external site if they click the 'Cancel' button on certain pages. This could be used in phishing campaigns to steal login credentials or distribute malware by making the malicious link appear to be part of the legitimate church management system.

Technical details

An open redirect vulnerability (CWE-601) exists in ChurchCRM due to insufficient validation of the 'linkBack' URL parameter across multiple components, including DonatedItemEditor.php. An attacker can craft a malicious URL containing an arbitrary destination in the 'linkBack' parameter and provide it to an authenticated user. When the victim interacts with the page and clicks the 'Cancel' button, the application uses the unvalidated parameter to perform a redirection. While the attack requires the victim to be authenticated, it can be triggered by users with low privileges. The issue is addressed in version 7.0.0.

Affected products

  • ChurchCRM ChurchCRM < 7.0.0

Timeline

  • 2026-04-03: disclosed: Initial advisory for DonatedItemEditor.php published
  • 2026-04-13: advisory: NVD published CVE-2026-39940
  • 2026-04-13: patched: Fix released in version 7.0.0

References