George Dawoud
13 exploits
Active since Oct 2025
ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`
ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}`
ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field
CVSS 5.4
ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function
CVSS 9.1
ChurchCRM: Username Enumeration via Differential Response in Public Login API
CVSS 5.3
ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion
CVSS 8.1
ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout
ChurchCRM has an XSS vulnerability
CVSS 6.1
Churchcrm < 5.19.0 - Missing Authentication
CVSS 7.3
ChurchCRM <6.2.0 - SQL Injection
CVSS 7.2
Churchcrm < 6.5.0 - SQL Injection
CVSS 7.2
Churchcrm < 6.5.0 - XSS
CVSS 6.5
ChurchCRM <6.7.2 - XSS
CVSS 5.4