This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: ChurchCRM < 7.1.0 has an **Authentication Bypass** in its API middleware. ๐ **Consequences**: Unauthenticated attackers can access **all protected API endpoints**, leading to total data compromise.
Q2Root Cause? (CWE/Flaw)
๐ก๏ธ **Root Cause**: **CWE-284** (Improper Access Control). The flaw lies in `ChurchCRM/Slim/Middleware/AuthMiddleware.php` due to improper URL handling in the API middleware.
Q3Who is affected? (Versions/Components)
๐ข **Affected**: **ChurchCRM** (Open Source CRM for Churches). ๐ฆ **Version**: All versions **prior to 7.1.0**. ๐งฉ **Component**: API Middleware.
Q4What can hackers do? (Privileges/Data)
๐ **Attacker Capabilities**: Access **unrestricted data** via protected APIs. ๐ **Privileges**: No authentication required. ๐ **Impact**: High Confidentiality & Integrity loss (CVSS: C:H, I:H).
๐ **Exploit**: **Yes**. Public PoC exists via Nuclei templates. ๐ **Method**: Crafted request URL with `api/public` path bypasses middleware checks.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for ChurchCRM instances. ๐งช **Test**: Send crafted requests to `/api/public` endpoints. ๐ก **Tool**: Use Nuclei template `CVE-2026-39339.yaml` for automated detection.
Q8Is it fixed officially? (Patch/Mitigation)
๐ฉน **Fix**: **Yes**. Official patch released in **Version 7.1.0**. ๐ข **Source**: GitHub Security Advisory (GHSA-v3p2-mx78-pxhc).
Q9What if no patch? (Workaround)
๐ง **Workaround**: If unpatched, **block external access** to `/api/public` endpoints via WAF or firewall rules. ๐ Restrict API middleware URL patterns.
Q10Is it urgent? (Priority Suggestion)
๐ฅ **Urgency**: **CRITICAL**. ๐จ CVSS Score indicates High Impact. โณ Immediate patching to v7.1.0 is strongly recommended to prevent data breaches.