← voltar
CVE-2026-39325

ChurchCRM has a Blind SQL injection in SettingsUser.php

CVSS 7.2 HIGHEPSS 0.3%CWE-89
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in ChurchCRM 7.0.5. Authenticated administrative users can inject arbitrary SQL statements through the type array parameter via the index and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
ChurchCRM · CRM

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →