EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
References
| Link | Resource |
|---|---|
| https://gist.github.com/NicolasPauferro/d877992327592f1e8eb4e2c9dce1ae9b | Exploit Third Party Advisory |
| https://github.com/phili67/ecclesiacrm/commit/f743b97f89da469a4c70b82bd61d0a59a3a957a9 | Patch |
| https://github.com/phili67/ecclesiacrm/pull/2861 | Issue Tracking Patch |
| https://github.com/phili67/ecclesiacrm/security/advisories/GHSA-gjw3-73q9-v2qh | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-06 20:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-35184
Mitre link : CVE-2026-35184
CVE.ORG link : CVE-2026-35184
JSON object : View
Products Affected
ecclesiacrm
- ecclesiacrm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
