SQL Injection Vulnerability Affects Church Admin from n/a through 4.0.27
CVE-2024-30244
8.5HIGH
Summary
A vulnerability exists in the Church Admin product developed by Andy Moyle, characterized by improper neutralization of special elements in SQL commands, leading to potential SQL injection attacks. This issue impacts versions from n/a through 4.0.27. Exploiting this vulnerability allows an attacker to manipulate database queries, potentially gaining unauthorized access to sensitive data. Organizations using affected versions should take immediate action to secure their systems.
Affected Version(s)
Church Admin <= 4.0.27
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)