← Back

Church Management System

church_management_system

Vendor: Church Management System Project • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Church Management System Project
1Church Management System
Jun 17, 2026
Nov 30, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
1Church Management System Project
1Church Management System
Jun 17, 2026
Oct 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
1Church Management System Project
1Church Management System
Jun 17, 2026
Sep 15, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
1Church Management System Project
1Church Management System
Jun 17, 2026
Sep 15, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
1Church Management System Project
1Church Management System
Jun 17, 2026
Sep 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.
1Church Management System Project
1Church Management System
Jun 17, 2026
Aug 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR...Show more
A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR (SELECT 7064 FROM(SELECT COUNT(*),CONCAT(0x71627a7671,(SELECT (ELT(7064=7064,1))),0x716b707871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- jURL leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205668.Show less
1Church Management System Project
1Church Management System
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on th...Show more
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.Show less
1Church Management System Project
1Church Management System
Jun 17, 2026
Oct 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.