An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows malicious users to execute arbitrary code via importing a crafted CSV file.
churchcrm churchcrm