| Summary | ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0. |
|---|---|
| Publication Date | April 18, 2026, 9:16 a.m. |
| Registration Date | April 19, 2026, 4:08 a.m. |
| Last Update | April 18, 2026, 9:16 a.m. |