SQL Injection Vulnerability in Church Donation System by Code-Projects
CVE-2025-7860

7.3HIGH

Key Information:

Vendor
CVE Published:
20 July 2025

What is CVE-2025-7860?

A SQL injection vulnerability has been identified in the Church Donation System 1.0, specifically in the processing of the login_admin.php file. This vulnerability allows attackers to manipulate input in the Username argument to execute arbitrary SQL queries. The attack can be initiated remotely, posing a significant risk to data integrity and system security. Given that the exploit has been disclosed, immediate action is recommended for users of the affected product to mitigate potential attacks.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-7860 : SQL Injection Vulnerability in Church Donation System by Code-Projects