Second Order SQL Injection Vulnerability in ChurchCRM Open Source Management System
CVE-2026-39319
8.8HIGH
What is CVE-2026-39319?
A second order SQL injection vulnerability exists in ChurchCRM, an open-source church management system, specifically within the /FundRaiserEditor.php endpoint. This flaw allows authenticated users, regardless of their privileges, to manipulate the iCurrentFundraiser PHP session parameter to inject arbitrary SQL statements, which could lead to unauthorized access and modification of sensitive database information. The vulnerability is addressed in version 7.1.0, making it essential for users to update to this version to safeguard their systems.
Affected Version(s)
CRM < 7.1.0
