Vulnerability record · CVE-2021-43258 · published 23 November 2022
CVE-2021-43258: Churchdb churchinfo unrestricted file upload vulnerability
Churchdb · Churchinfo
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.
Description
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.churchdb.org/ | Product |
| https://github.com/rapid7/metasploit-framework/pull/17257 | ExploitPatchThird Party Advisory |
| https://sourceforge.net/projects/churchinfo/files/ | Product |
| http://www.churchdb.org/ | Product |
| https://github.com/rapid7/metasploit-framework/pull/17257 | ExploitPatchThird Party Advisory |
| https://sourceforge.net/projects/churchinfo/files/ | Product |
Track CVE-2021-43258 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-43258), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.