PT-2025-30296 · Code Projects · Church Donation System
N0Name
·
Published
2025-07-21
·
Updated
2025-07-21
·
CVE-2025-7929
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
code-projects Church Donation System version 1.0
Description
A critical issue exists in code-projects Church Donation System 1.0. The manipulation of the
fname argument in the /members/edit Members.php file leads to SQL injection. This allows for remote exploitation. The exploit has been publicly disclosed. Other parameters may also be affected.Recommendations
As a temporary workaround, consider restricting access to the
/members/edit Members.php file to minimize the risk of exploitation.
Sanitize the fname parameter before using it in SQL queries.
Review and sanitize all other parameters used in SQL queries within the application.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Church Donation System