


Perceptive Security
SOC/SIEM Consultancy

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration…
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 19:08:14
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Enterprise Applications
ChurchCRM, an open-source church management system, contains a SQL injection vulnerability in PropertyTypeEditor.php prior to version 7.1.0. The vulnerability was introduced when legacyFilterInput() function was replaced with sanitizeText(), removing SQL escaping protection. Authenticated users with MenuOptions role can exploit this to perform time-based blind injection attacks and exfiltrate database data including password hashes. The vulnerability exists in the administration functionality for managing property type categories. Fixed in version 7.1.0.
Technical details
Mitigation steps:
Affected products:
ChurchCRM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39340
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-66f7-4p96-mww9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
