#VU125713 SQL injection in ChurchCRM - CVE-2024-39304
Published: July 26, 2024 / Updated: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to manipulate the database and disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the EID parameter in /GetText.php when handling a GET request. A remote user can send a specially crafted request to manipulate the database and disclose sensitive information.
The issue is a blind SQL injection.