This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A code injection flaw in ChurchCRM's installation wizard. ๐ฅ **Consequences**: The `$dbPassword` variable is uncleaned, leading to **Pre-authentication Remote Code Execution (RCE)**.โฆ
๐ก๏ธ **Root Cause**: **CWE-94** (Code Injection). ๐ **Flaw**: The installation wizard fails to sanitize the `$dbPassword` input variable before execution.โฆ
๐ข **Vendor**: ChurchCRM. ๐ฆ **Product**: CRM System. ๐ **Affected Versions**: All versions **prior to 7.1.0**. If you are running v7.0.x or earlier, you are vulnerable.
Q4What can hackers do? (Privileges/Data)
๐ **Privileges**: **Pre-authentication** access. No login needed! ๐๏ธ **Data**: Full **Remote Code Execution**. Hackers can execute system commands, install backdoors, and take over the entire server infrastructure.
Q5Is exploitation threshold high? (Auth/Config)
๐ **Threshold**: **Extremely Low**. ๐ช **Auth**: **None required** (Pre-auth). ๐ **Network**: Remote (AV:N). ๐ฏ **Complexity**: Low (AC:L). This is a critical, easy-to-exploit flaw.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exp?**: **Yes**. A GitHub Security Advisory (GHSA-pm2v-ggh4-mp7p) has been published. While specific PoC code isn't listed in the snippet, the advisory confirms the vulnerability is known and exploitable.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: 1. Check your ChurchCRM version. 2. Look for the **Installation Wizard** endpoint. 3. Scan for unhandled `$dbPassword` parameters in POST requests during setup. 4.โฆ
๐ง **Fix**: **Yes**. Upgrade to **ChurchCRM 7.1.0** or later. The vendor has acknowledged the issue via GitHub Security Advisory and released a patch to sanitize the input.
Q9What if no patch? (Workaround)
๐ง **Workaround**: If patching is impossible: 1. **Block** access to the installation wizard from the internet. 2. Ensure the installation wizard is **disabled** or removed in production. 3.โฆ
๐ฅ **Urgency**: **CRITICAL**. ๐จ **Priority**: **Immediate Action Required**. With **CVSS 9.8** (High) and **Pre-auth RCE**, this is a top-priority vulnerability. Patch immediately to prevent total server compromise.