Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in ChurchCRM. Authenticated users with the role isMenuOptionsEnabled can inject arbitrary SQL statements through the Name and Description parameters and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0. | |
| Title | ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T19:59:29.975Z
Reserved: 2026-04-06T19:31:07.267Z
Link: CVE-2026-39326
Updated: 2026-04-07T19:14:10.686Z
Status : Received
Published: 2026-04-07T18:16:43.690
Modified: 2026-04-07T20:16:28.927
Link: CVE-2026-39326
No data.
OpenCVE Enrichment
No data.