top of page
perceptive_background_267k.jpg

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration…

Published:

6 april 2026 om 22:00:00

Alert date:

7 april 2026 om 19:08:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Enterprise Applications

ChurchCRM, an open-source church management system, contains a SQL injection vulnerability in PropertyTypeEditor.php prior to version 7.1.0. The vulnerability was introduced when legacyFilterInput() function was replaced with sanitizeText(), removing SQL escaping protection. Authenticated users with MenuOptions role can exploit this to perform time-based blind injection attacks and exfiltrate database data including password hashes. The vulnerability exists in the administration functionality for managing property type categories. Fixed in version 7.1.0.

Technical details

Mitigation steps:

Affected products:

ChurchCRM

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page