CVE-2026-35184 Details
Description
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
A SQL injection vulnerability has been identified in EcclesiaCRM versions prior to 8.0.0. The issue resides in the Query Viewer component, specifically within the file v2/templates/query/queryview.php. The vulnerability allows authenticated users to inject arbitrary SQL commands through the custom and value parameters, bypassing normal query logic. This exploitation can lead to unauthorized access to sensitive database information, including personal member details, financial records, and administrative credentials.
Users are advised to update to EcclesiaCRM version 8.0.0 or later, where this vulnerability has been fixed. For those using earlier versions, it is recommended to avoid granting database query access rights to users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/NicolasPauferro/d877992327592f1e8eb4e2c9dce1ae9b | [email protected] | ExploitThird Party Advisory |
| https://github.com/phili67/ecclesiacrm/commit/f743b97f89da469a4c70b82bd61d0a59a3a957a9 | [email protected] | Patch |
| https://github.com/phili67/ecclesiacrm/pull/2861 | [email protected] | Issue TrackingPatch |
| https://github.com/phili67/ecclesiacrm/security/advisories/GHSA-gjw3-73q9-v2qh | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ecclesiacrm ecclesiacrm | < 8.0.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | New CVE Received | [email protected] |