CVE-2023-24685

Published
View on NVD ↗
CVSS v3
7.2
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

ChurchCRM - A free and open-source Church Management Software (ChMS) to help churches manage their membership data, groups, events, and finances.
GitHubGitHub
890