#VU125686 SQL injection in ChurchCRM
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary SQL queries.
The vulnerability exists due to SQL injection in src/EventEditor.php when handling the EID POST parameter during event editing. A remote privileged user can send a specially crafted POST request to execute arbitrary SQL queries.
Exploitation requires event management permissions associated with the isAddEvent capability.