First published: Fri Mar 21 2025(Updated: )
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/soulwinning_crud.php. The manipulation of the argument photo/photo1 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Best Church Management Software | ||
Church Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2606 is categorized as a critical vulnerability.
To mitigate CVE-2025-2606, restrict access to the file /admin/app/soulwinning_crud.php and ensure proper validation of user inputs.
CVE-2025-2606 may allow unauthorized access and manipulation of sensitive data within the SourceCodester Best Church Management Software.
CVE-2025-2606 affects SourceCodester Best Church Management Software version 1.0.
To determine if your system is vulnerable to CVE-2025-2606, check if you are using SourceCodester Best Church Management Software version 1.0 and assess the security of the specified functionality.