PT-2026-30889 · Churchcrm · Churchcrm

Sh4Dowalker

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35567

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.1.0
Description ChurchCRM is an open-source church management system susceptible to SQL injection. The NewRole POST parameter in src/MemberRoleChange.php is used in an SQL query without sufficient integer validation. This allows authenticated users with the ManageGroups role to inject arbitrary SQL, requiring knowledge of a valid GroupID and PersonID, obtainable from GroupView or PersonView pages.
Recommendations Update to version 7.1.0 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35567

Affected Products

Churchcrm