SQL injection in ChurchCRM - #VU125686
Published: April 9, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary SQL queries.
The vulnerability exists due to SQL injection in src/EventEditor.php when handling the EID POST parameter during event editing. A remote privileged user can send a specially crafted POST request to execute arbitrary SQL queries.
Exploitation requires event management permissions associated with the isAddEvent capability.