Horizon Alert
Summary of the vulnerability and why it matters
This advisory describes a critical vulnerability in ChurchCRM, an open-source church management system, that could allow an authenticated user to inject malicious SQL code through its advanced search feature. If exploited, this could lead to unauthorized access, modification, or deletion of sensitive church data. The issue has been addressed in version 7.1.0.
- SQL injection risk in church management software.
- Authenticated users can potentially access sensitive data.
- Confirm relevance and exposure to ChurchCRM installations.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to ChurchCRM could exploit a SQL injection vulnerability to access or modify sensitive church data. This attack begins by logging into the system and navigating to the "Advanced Search" feature within the Data/Reports section. By manipulating the `searchwhat` parameter in a specific query, the attacker can inject malicious SQL code, leading to unauthorized data access or manipulation.
- Authenticated user access required.
- Malicious input targets search parameter.
- Risk of data compromise or alteration.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an authenticated user with specific access to reporting features could exploit a SQL injection vulnerability in ChurchCRM. This could potentially allow unauthorized access to sensitive church member data or alter system behavior related to queries.
- Church member data.
- SQL injection via advanced search.
- Unauthorized data access or modification.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners are likely responsible for ChurchCRM, as it's a self-hosted application requiring authenticated access to specific modules for exploitation. The first practical move is to identify all ChurchCRM instances, confirm their reachability and business criticality, and then engage the system's accountable owner to plan remediation based on risk.
- Identify ChurchCRM instances and owners.
- Verify user access and data criticality.
- Plan vendor-coordinated updates.