Vulnerabilities > Church Management System Project > Church Management System > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-06-13 | CVE-2021-41661 | SQL Injection vulnerability in Church Management System Project Church Management System 1.0 Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. | 9.8 |
2021-10-29 | CVE-2021-41643 | Unrestricted Upload of File with Dangerous Type vulnerability in Church Management System Project Church Management System 1.0 Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. | 9.8 |