churchdb CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

churchdb vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to churchdb, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-43258 CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded [email protected] 8.8 78.75% 2022-11-23 2025-04-28
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence