CRITICAL🇵🇱 Wersja polska

CVE-2026-39342

CVSS 9.4v4.0pub. 2026-04-07upd. 2026-07-24

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation and sanitization of input data passed through the searchwhat parameter in a request to QueryView.php with the QueryID=15 parameter. An attacker with access to the Data/Reports > Query Menu section and the 'Advanced Search' query can inject malicious SQL code into the query executed by the application. This enables manipulation of the logic of queries directed to the database.

Impact

An attacker can gain unauthorized access to data stored in the database, modify or delete data, and depending on the environment configuration, potentially escalate their privileges in the system.

Mitigation & patch

ChurchCRM should be updated to version 7.1.0, in which the vulnerability has been fixed.

Who is affected

ChurchCRM in versions prior to 7.1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Churchcrm

    APP
    Churchcrm
    < 7.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-39339CRITICAL9.1PL ✓same product

ChurchCRM — krytyczny auth bypass w API middleware

CVE-2026-39337CRITICAL10.0PL ✓same product

ChurchCRM: pre-auth RCE przez wstrzyknięcie kodu PHP w kreatorze instalacji

CVE-2026-35573CRITICAL9.1PL ✓same product

ChurchCRM: Path Traversal i RCE przez funkcję przywracania kopii zapasowej

CVE-2025-68110CRITICAL9.9PL ✓same product

ChurchCRM: ujawnienie danych logowania do bazy danych w komunikacie błędu

CVE-2025-67876CRITICAL9.3PL ✓same product

Stored XSS w ChurchCRM — przejęcie konta przez nazwy ról grup