#VU125708 SQL injection in ChurchCRM - CVE-2026-39330
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to disclose and modify database information.
The vulnerability exists due to SQL injection in the /PropertyAssign.php endpoint when handling the Value POST parameter. A remote user can send a specially crafted request to disclose and modify database information.
Exploitation requires the Manage Groups & Roles and Edit Records permissions.