CVE-2026-35578 Details
Description
Rejected reason: This CVE is a duplicate of another CVE.** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39940. Reason: This candidate is a reservation duplicate of CVE-2026-39940. Notes: All CVE users should reference CVE-2026-39940 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
An open redirect vulnerability has been identified in ChurchCRM, an open-source church management system, in versions prior to 7.0.0. The issue arises in multiple locations within the application where the 'linkBack' URL parameter is used. The application fails to validate this parameter, allowing attackers to specify arbitrary URLs. When an authenticated user clicks the 'Cancel' button on the affected page, they are redirected to the attacker-controlled URL without any safety checks.
Users are advised to update to ChurchCRM version 7.0.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Apr 13, 2026 | CVE Rejected | [email protected] |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Apr 9, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | New CVE Received | [email protected] |