CVE-2024-39304

HIGH

Churchcrm < 5.9.2 - SQL Injection

Title source: rule

Description

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges are necessary. This allows attackers to inject SQL statements directly into the database query due to inadequate sanitization of the EID parameter in in a GET request to `/GetText.php`. Version 5.9.2 patches the issue.

Exploits (2)

exploitdb WORKING POC
by Sanan Qasimzada · webappsphp
https://www.exploit-db.com/exploits/52152
nomisec WORKING POC 1 stars
by apena-ba · poc
https://github.com/apena-ba/CVE-2024-39304

Scores

CVSS v3 8.8
EPSS 0.0346
EPSS Percentile 87.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
churchcrm/churchcrm < 5.9.2
Published Jul 26, 2024
Tracked Since Feb 18, 2026