# CVE-2025-68109

## Summary

- **CVE ID:** CVE-2025-68109
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-78, CWE-434, CWE-494, CWE-552, CWE-915
- **Published:** Dec 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct access to it. Once accessed, the uploaded web shell allows remote code execution (RCE) on the server. Version 6.5.3 fixes the issue.

## Affected Products

- ChurchCRM — CRM (< 6.5.3)

## References

- [CNA](https://github.com/ChurchCRM/CRM/security/advisories/GHSA-pqm7-g8px-9r77)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.57%
- **EPSS Percentile:** 73.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._