← Volver a CVEs
CVE-2026-39319
HIGH8.8
Descripcion
ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't need any privileges. These users can inject arbitrary SQL statements through the iCurrentFundraiser PHP session parameter and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado4/7/2026
Ultima modificacion4/10/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
churchcrm:churchcrm
Debilidades (CWE)
CWE-89
Referencias
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-vg4m-hc29-jgqj(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.