SQL Injection Vulnerability in ChurchCRM by ChurchCRM
CVE-2023-38760
7.5HIGH
What is CVE-2023-38760?
An SQL injection vulnerability exists in ChurchCRM v.5.0.0 that permits remote attackers to exploit the system by manipulating the role and gender parameters within the /QueryView.php component, potentially leading to unauthorized access to sensitive information.