EIP-2026-105843

PRE-CVE

Church Management System 1.0 - 'search' SQL Injection (Unauthenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105843. PoCs published by Erwin Krazek.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated SQL Injection vulnerability in Church Management System 1.0 via the 'search' parameter. The provided SQLmap commands confirm the vulnerability and show successful database enumeration.

Description

Church Management System 1.0 - 'search' SQL Injection (Unauthenticated)

Exploits (1)

exploitdb WORKING POC
by Erwin Krazek · textwebappsphp
https://www.exploit-db.com/exploits/50303

This exploit demonstrates an unauthenticated SQL Injection vulnerability in Church Management System 1.0 via the 'search' parameter. The provided SQLmap commands confirm the vulnerability and show successful database enumeration.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Church Management System 1.0
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026