Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2022-45328

Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
Attacker Value
Unknown

CVE-2022-41406

Disclosure Date: October 12, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-38595

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
Attacker Value
Unknown

CVE-2022-38594

Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
Attacker Value
Unknown

CVE-2022-38605

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.
Attacker Value
Unknown

CVE-2022-2680

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR (SELECT 7064 FROM(SELECT COUNT(*),CONCAT(0x71627a7671,(SELECT (ELT(7064=7064,1))),0x716b707871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- jURL leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205668.
Attacker Value
Unknown

CVE-2021-41661

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
Attacker Value
Unknown

CVE-2022-1084

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched remotely.
Attacker Value
Unknown

CVE-2022-1080

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely.
Attacker Value
Unknown

CVE-2022-1079

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are multiple files and parameters which are prone to to cross site scripting. It is possible to launch the attack remotely.