๐Ÿ” CVE Alert

CVE-2026-6628

MEDIUM 6.3

phili67 Ecclesia CRM Query Viewer view ValidateInput sql injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query Viewer Component. This manipulation of the argument custom causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-89 CWE-74
Vendor phili67
Product ecclesia crm
Published Apr 20, 2026
Last Updated Apr 20, 2026
Stay Ahead of the Next One

Get instant alerts for phili67 ecclesia crm

Be the first to know when new medium vulnerabilities affecting phili67 ecclesia crm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

phili67 / Ecclesia CRM
8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/358262 vuldb.com: https://vuldb.com/vuln/358262/cti vuldb.com: https://vuldb.com/submit/792607 github.com: https://github.com/NicolasPauferro/studiessqli

Credits

๐Ÿ” Nicolas Pauferro (VulDB User) VulDB CNA Team