SQL injection in ChurchCRM - CVE-2026-39340

 

SQL injection in ChurchCRM - CVE-2026-39340

Published: April 9, 2026


Vulnerability identifier: #VU125700
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39340
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify arbitrary database records.

The vulnerability exists due to SQL injection in PropertyTypeEditor.php when processing Name and Description fields in property type save requests. A remote user can send specially crafted input to disclose sensitive information and modify arbitrary database records.

Exploitation requires the MenuOptions role and can be performed through the administration functionality for managing people and family property type categories.


Affected software

ChurchCRM

How to mitigate CVE-2026-39340

Install security update from vendor's website.

ChurchCRM - update to 7.1.0

External References

Related Security Bulletins