SQL Injection Vulnerability in ChurchCRM Open-Source Management System
CVE-2026-40482
7.1HIGH
What is CVE-2026-40482?
ChurchCRM, an open-source church management system, suffers from a SQL injection vulnerability that affects versions before 7.2.0. The flaw exists due to the unsanitized concatenation of the variable $routeAndAccount into raw SQL within the FinancialService::getMemberByScanString() function. This vulnerability could potentially allow attackers to execute arbitrary SQL commands, leading to unauthorized access to sensitive information in the database. The issue has been addressed in version 7.2.0, emphasizing the importance of updating to this version to maintain security and safeguard user data.
Affected Version(s)
CRM < 7.2.0
