What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.0.27.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.0.27.
Explanation of Vulnerability in Simple Terms
Church Admin versions 4.0.27 and earlier contain a SQL injection vulnerability in a database query that processes user input without proper sanitization. An attacker with low-level user access can craft malicious input to extract sensitive data from the database or disrupt site availability. The vulnerability affects the entire application scope due to database access.
What an attacker can do
Read sensitive data from the database or cause the site to become unavailable.
Potential impact on your site
Unauthorized access to database records and potential service disruption for Church Admin installations.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities