Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in ChurchCRM's SettingsIndividual.php where user-controlled array keys from the type POST parameter are used directly in SQL queries without sanitization. This allows any authenticated user to extract sensitive data from the database. This vulnerability is fixed in 7.1.0. | |
| Title | ChurchCRM has a SQL Injection via Unsanitized Array Keys in SettingsIndividual.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T19:59:36.789Z
Reserved: 2026-04-06T19:31:07.266Z
Link: CVE-2026-39317
Updated: 2026-04-07T19:47:05.389Z
Status : Received
Published: 2026-04-07T18:16:42.667
Modified: 2026-04-07T20:16:28.580
Link: CVE-2026-39317
No data.
OpenCVE Enrichment
No data.