SQL Injection Vulnerability in Campcodes Church Management System
CVE-2024-3540
Key Information:
- Vendor
- Campcodes
- Status
- Vendor
- CVE Published:
- 10 April 2024
Badges
Summary
A significant security vulnerability has been identified in the Campcodes Church Management System version 1.0, specifically within the file /admin/add_sundaysch.php. This vulnerability arises from improper handling of the 'Gender' parameter, which can be exploited to execute SQL injection attacks. Attackers can leverage this flaw remotely to gain unauthorized access to the underlying database, potentially exposing sensitive information or compromising the entire system. The issue has been disclosed publicly, and it is crucial for users of this software to apply relevant security patches and take preventative measures to mitigate the threat.
Affected Version(s)
Church Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved