PT-2026-33750 · Phili67 · Ecclesiacrm
Nicolas Pauferro
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6628
CVSS v2.0
6.5
Medium
| AV:N/AC:L/Au:S/C:P/I:P/A:P |
A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ecclesiacrm