SourceCodester Best Church Management Software SQL Injection Vulnerability

Vulnerability

A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue resides in the file '/admin/app/slider_crud.php', where the 'del_id' parameter can be manipulated to execute unauthorized SQL commands. This vulnerability allows remote attackers to perform time-based blind SQL injection, potentially leading to data extraction from the application's database.

Impact

Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate database queries to extract information from the database.

Reproduction

To reproduce this vulnerability, send a POST request to '/admin/app/slider_crud.php' with the 'del_id' parameter. The application will process the request and execute the SQL query with the provided 'del_id' value, allowing for SQL injection exploitation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.