漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Incomplete fix for CVE-2026-35184: SQL Injection in phili67/ecclesiacrm
Vulnerability Description
EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query parameters that use non-standard validation types. This is caused by an incomplete fix for CVE-2026-35184.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
EcclesiaCRM SQL注入漏洞
Vulnerability Description
EcclesiaCRM是法国phili67个人开发者的一款用于教会管理的客户关系管理软件。 EcclesiaCRM 8.0.0及之前版本存在SQL注入漏洞,该漏洞源于ValidateInput函数的默认情况通过str_replace将用户提供的POST参数直接传递到SQL查询中且未进行清理,导致SQL注入。
CVSS Information
N/A
Vulnerability Type
N/A