SSRF via Referrer field in ChurchCRM v5.16.0
ChurchCRM doesn't validate the referrer properly and sends a HEAD request to the provided referrer. When a user is logged in and does a GET request to the Dashboard for example with an external referrer, a HEAD request is sent.