CVE-2025-7860
published 2025-07-20CVE-2025-7860: A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.39%
31.6th percentile
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/login_admin.php. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| carmelo | church_donation_system | — | — |
| code-projects | church_donation_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MS SWIFT WEB-UI RCE Vulnerability
ghsa·2025-07-31
CVE-2025-41419 [MEDIUM] CWE-117 MS SWIFT WEB-UI RCE Vulnerability
MS SWIFT WEB-UI RCE Vulnerability
**I. Detailed Description:**
This includes scenarios, screenshots, vulnerability reproduction methods. For account-related vulnerabilities, please provide test accounts. If the reproduction process is complex, you may record a video, upload it to Taopan, and attach the link.
1. Install ms-swift
```
pip install ms-swift -U
```
2. Start web-ui
```
swift web-ui --lang en
```
3. After startup, access through browser at [http://localhost:7860/](http://localhost:7860/) to see the launched fine-tuning framework program
4. Fill in necessary parameters
In the LLM Training interface, fill in required parameters including Model id, Dataset Code. The --output_dir can be filled arbitrarily as it will be modified later through packet capture
5. Click Begin to sta
GHSA
GHSA-fhx3-5625-8mwv: A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1
ghsa_unreviewed·2025-07-20
CVE-2025-7860 [MEDIUM] CWE-74 GHSA-fhx3-5625-8mwv: A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/login_admin.php. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
No detection rules found.
No writeups or analysis indexed.
2025-07-20
Published