1. ChurchCRM 4.4.5 Exposes Critical SQL Injection Flaw in 'Why Came' Editor
A critical SQL injection vulnerability has been publicly disclosed in ChurchCRM version 4.4.5, exposing the church management software's database to potential compromise. The flaw resides in the `/churchcrm/WhyCameEditor.php` endpoint, specifically within the `PersonID` parameter. The vulnerability is exploitable by an...