PT-2026-30889 · Churchcrm · Churchcrm
Sh4Dowalker
·
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-35567
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 7.1.0
Description
ChurchCRM is an open-source church management system susceptible to SQL injection. The
NewRole POST parameter in src/MemberRoleChange.php is used in an SQL query without sufficient integer validation. This allows authenticated users with the ManageGroups role to inject arbitrary SQL, requiring knowledge of a valid GroupID and PersonID, obtainable from GroupView or PersonView pages.Recommendations
Update to version 7.1.0 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Churchcrm