peter bassill · operator
$ cve CVE-2024-39304 JSON

CVE-2024-39304 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges are necessary. This allows attackers to inject SQL statements directly into the database query due to inadequate sanitization of the EID parameter in in a GET request to `/GetText.php`. Version 5.9.2 patches the issue.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS2.98% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2024-07-26
Last modified2026-06-17

Affected (1)

VendorProduct
churchcrmchurchcrm

Public exploits

SourceTitleDate
exploit-dbChurchCRM 5.9.1 - SQL Injection2025-04-09

References

→ the Explorer  ·  watch your stack  ·  NVD