SQL Injection Vulnerability in ChurchCRM by ChurchCRM
CVE-2023-38763
6.5MEDIUM
What is CVE-2023-38763?
An SQL injection vulnerability exists in ChurchCRM v.5.0.0 that enables remote attackers to exploit the FundRaiserID parameter in the /FundRaiserEditor.php endpoint. Successful exploitation could allow attackers to access sensitive information stored in the database, posing significant risks to data security.