VendorsChurch Management System Projectchurch_management_system1.0
Vulnerabilities

Church Management System Project Church Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-41643
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
Published 2021-10-29 · Modified
9.8EPSS 0.046
CVE-2021-41661
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
Published 2022-06-13 · Modified
9.8EPSS 0.013
CVE-2022-2680
SourceCodester Church Management System login.php sql injection
Published 2022-08-05 · Modified
8.8EPSS 0.007
CVE-2022-41406
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-10-11 · Modified
7.2EPSS 0.012
CVE-2022-38605
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.
Published 2022-09-12 · Modified
7.2EPSS 0.010
CVE-2022-38594
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
Published 2022-09-15 · Modified
7.2EPSS 0.009
CVE-2022-38595
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
Published 2022-09-15 · Modified
7.2EPSS 0.009
CVE-2022-45328
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
Published 2022-11-30 · Modified
7.2EPSS 0.007