SQL Injection Vulnerability Affects Church Admin from n/a through 4.0.27
CVE-2024-30244

8.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
28 March 2024

Summary

A vulnerability exists in the Church Admin product developed by Andy Moyle, characterized by improper neutralization of special elements in SQL commands, leading to potential SQL injection attacks. This issue impacts versions from n/a through 4.0.27. Exploiting this vulnerability allows an attacker to manipulate database queries, potentially gaining unauthorized access to sensitive data. Organizations using affected versions should take immediate action to secure their systems.

Affected Version(s)

Church Admin <= 4.0.27

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.