Record summary

CVE-2024-39304 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges are necessary. This allows attackers to inject SQL statements directly into the database query due to inadequate sanitization of the EID parameter in in a GET request to `/GetText.php`. Version 5.9.2 patches the issue.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 5.9.2affected

Default status: unknown

CVE ListBefore 5.9.2affected

Proofs of concept

2

Catalogued exploits

ExploitDBChurchCRM 5.9.1 - SQL InjectionExploitDB exploitby Sanan QasimzadaNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubapena-ba/CVE-2024-39304Repository PoCby apena-baStars: 1Not analyzed2 files

3.3 KiB

GitHub

PoC details

References

2