SourceCodester Best Church Management Software
- 1.1
A critical SQL injection vulnerability has been identified in SourceCodester Best Church Management Software version 1.1. The issue arises in the file '/admin/app/profile_crud.php', where improper handling of the 'username' parameter allows remote attackers to execute time-based blind SQL injection, potentially leading to unauthorized data extraction from the database.
Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries to extract information from the application's database.
To reproduce this vulnerability, send a POST request to '/admin/app/profile_crud.php' with the 'update' parameter set to '1' and the 'username' parameter containing the crafted SQL injection payload. The application will process the request, allowing the injected SQL code to be executed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.