SQL Injection Vulnerability in ChurchCRM by ChurchCRM
CVE-2023-38765
7.5HIGH
What is CVE-2023-38765?
A SQL injection vulnerability in ChurchCRM version 5.0.0 allows remote attackers to exploit the membermonth parameter within the /QueryView.php file, potentially enabling unauthorized access to sensitive information stored in the database. This weakness can be exploited to extract confidential data, posing significant privacy risks for users.