VYPR

Churchinfo

by Churchdb

CVEs (1)

  • CVE-2021-43258HigNov 23, 2022
    risk 0.04cvss 8.8epss 0.11

    CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment…