Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-31325: SQL Injection vulnerability in ChurchCRM 4.4.5 via /churchcrm/WhyCameEditor.php · Issue #6005 · ChurchCRM/CRM

There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the ‘PersonID’ field in /churchcrm/WhyCameEditor.php.

CVE
#sql#vulnerability#php#auth

Isn’t admin allowed to make arbitrary SQL queries using QuerySQL.php?

Correct. However, we should be sanitising input appropriately on forms etc. Personally, I’m not a huge fan of the QuerySQL.php but it has made some support cases a lot easier - especially when not all admins are comfortable with phpMyAdmin or CLI MySQL tools.

@tuando243 - thanks for the report. I’ve categorised it as a security bug, but as it requires authenticated access it has limited risk to most setups (except our demo system!).

Related news

ChurchCRM 4.4.5 SQL Injection

ChurchCRM version 4.4.5 suffers from a remote SQL injection vulnerability.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907