A SQL injection vulnerability exists in ChurchCRM prior to 6.7.2 in the /PaddleNumEditor.php endpoint. An authenticated attacker can supply crafted input via the PerID parameter to influence backend SQL query execution due to insufficient sanitization/parameterization, enabling unauthorized database query manipulation. The issue is exploitable by any authenticated user, including accounts with zero assigned permissions. ChurchCRM 6.7.2 includes a patch.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
PerID parameter, potentially enabling unauthorized read/modify operations on database contents and, depending on database configuration and application context, broader compromise of application data integrity and confidentiality.If you can’t patch tonight, do this now.
/PaddleNumEditor.php to only trusted roles/users, enforce strict server-side input validation for PerID (e.g., numeric-only with bounds checking), and ensure database queries use parameterized statements/prepared queries. Additionally, monitor and alert on anomalous requests to /PaddleNumEditor.php and suspicious SQL error patterns in logs.Patch, then assume compromise.
/PaddleNumEditor.php affecting the PerID parameter.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python PoC script and a README. - Primary file: `CVE-2026-24854- SQL Injection in ChurchCRM.PY` (Python 3). It uses `requests.Session()` to authenticate to a ChurchCRM instance (`POST /Login.php`) and then sends crafted POST requests to the vulnerable endpoint (`POST /PaddleNumEditor.php`). The exploit targets the `PerID` POST parameter, injecting a numeric-context payload like `0 OR 1=1 -- ` to manipulate SQL query logic (e.g., bypassing WHERE clauses). The script demonstrates a normal request (`PerID=1`) versus an injected request and includes a tunable `is_success_response()` heuristic to detect behavioral differences. - Vulnerability/impact: Authenticated numeric SQL injection (logic manipulation) in ChurchCRM < 6.7.2 (fixed in 6.7.2; referenced fix commit `748f5084`). The PoC emphasizes destructive/logic-abuse outcomes (multi-row/full-table UPDATE/DELETE/INSERT) rather than data extraction. - Repository purpose: Provide a reproducible research PoC for CVE-2026-24854, including operator guidance to copy all real form fields from a legitimate request and then override only `PerID` to trigger unintended bulk database operations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.