ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0.
The vulnerability results from insufficient validation and sanitization of input data passed through the searchwhat parameter in a request to QueryView.php with the QueryID=15 parameter. An attacker with access to the Data/Reports > Query Menu section and the 'Advanced Search' query can inject malicious SQL code into the query executed by the application. This enables manipulation of the logic of queries directed to the database.
An attacker can gain unauthorized access to data stored in the database, modify or delete data, and depending on the environment configuration, potentially escalate their privileges in the system.
ChurchCRM should be updated to version 7.1.0, in which the vulnerability has been fixed.
ChurchCRM in versions prior to 7.1.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XChurchcrm
APPChurchcrm< 7.1.0
Related vulnerabilities
ChurchCRM — krytyczny auth bypass w API middleware
ChurchCRM: pre-auth RCE przez wstrzyknięcie kodu PHP w kreatorze instalacji
ChurchCRM: Path Traversal i RCE przez funkcję przywracania kopii zapasowej
ChurchCRM: ujawnienie danych logowania do bazy danych w komunikacie błędu
Stored XSS w ChurchCRM — przejęcie konta przez nazwy ról grup