ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 17 Apr 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0. | |
| Title | ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}` | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-17T22:58:48.528Z
Reserved: 2026-04-13T19:50:42.114Z
Link: CVE-2026-40482
No data.
Status : Received
Published: 2026-04-18T00:16:39.110
Modified: 2026-04-18T00:16:39.110
Link: CVE-2026-40482
No data.
OpenCVE Enrichment
Updated: 2026-04-18T09:00:05Z
Weaknesses