A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:22:25.719Z

Reserved: 2021-10-04T00:00:00

Link: CVE-2021-41965

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-15T11:15:10.377

Modified: 2024-11-21T06:27:00.310

Link: CVE-2021-41965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.