Description
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
References
github.com/...siacrm/security/advisories/GHSA-gjw3-73q9-v2qh
github.com/phili67/ecclesiacrm/pull/2861
github.com/...ommit/f743b97f89da469a4c70b82bd61d0a59a3a957a9
gist.github.com/...Pauferro/d877992327592f1e8eb4e2c9dce1ae9b