PT-2026-30945 · Churchcrm · Churchcrm

Sh4Dowalker

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-39323

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.1.0
Description A critical SQL injection issue exists in ChurchCRM's PropertyTypeEditor.php. The Name and Description POST parameters are insufficiently sanitized using only strip tags() before being directly incorporated into SQL queries. This allows authenticated users with 'Manage Properties' permission to execute arbitrary SQL commands, potentially leading to data exfiltration, modification, and deletion. Injected data persists in the database and is reflected across multiple application pages without output encoding.
Recommendations Update to version 7.1.0 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-39323

Affected Products

Churchcrm