SQL injection in ChurchCRM - CVE-2026-39327
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose and modify sensitive information.
The vulnerability exists due to SQL injection in the /MemberRoleChange.php endpoint when processing the NewRole parameter in POST requests. A remote user can send a specially crafted request to disclose and modify sensitive information.
Exploitation requires the Manage Groups & Roles (ManageGroups) role.