SQL Injection Vulnerability in ChurchCRM by ChurchCRM Inc.
CVE-2023-38773
7.5HIGH
What is CVE-2023-38773?
An SQL injection vulnerability exists in ChurchCRM version 5.0.0, enabling remote attackers to exploit insecure parameters (volopp1 and volopp2) in the /QueryView.php file. This vulnerability may allow unauthorized access to sensitive information stored within the database, potentially leading to data breaches and compromise of user data.