Junglewise Threat Intelligence

CVE-2026-39341: ChurchCRM SQL injection in ConfirmReportEmail.php

CVE-2026-39341 · Severity: high · CVSS 8.1 · Published 2026-04-07

Technologies: ChurchCRM. Vendors: ChurchCRM.

Executive brief

ChurchCRM, an open-source church management system, is vulnerable to a security flaw that allows attackers to interfere with its database. By sending specially crafted requests to a specific report generation page, an authorized user can trick the system into executing unintended database commands. This could lead to the theft of sensitive member information or unauthorized changes to church records.

Technical details

A time-based SQL injection vulnerability exists in ChurchCRM versions prior to 7.1.0. The flaw is located in the `src/Reports/ConfirmReportEmail.php` endpoint, specifically within the `familyId` GET parameter. Although the application attempts to filter the input using `InputUtils::legacyFilterInput`, the original unsanitized `$_GET['familyId']` value is used to construct the SQL query instead of the sanitized result. An authenticated attacker can exploit this by injecting SQL syntax (e.g., using `SLEEP()` commands) to extract data or manipulate the database. The issue is resolved in version 7.1.0.

Affected products

  • ChurchCRM CRM < 7.1.0

Timeline

  • 2026-04-05: advisory: GitHub Security Advisory published
  • 2026-04-07: disclosed: CVE-2026-39341 published
  • 2026-04-07: patched: Fix released in version 7.1.0

References

Related threats