Aller au contenu

Fiche vulnérabilité

CVE-2024-39304 : faille élevée churchcrm churchcrm (CVSS 8.8)

Description

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges are necessary. This allows attackers to inject SQL statements directly into the database query due to inadequate sanitization of the EID parameter in in a GET request to `/GetText.php`. Version 5.9.2 patches the issue.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 juil. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • churchcrm churchcrm

Références

Rechercher une autre vulnérabilité dans la base CVE