EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:churchcrm:churchcrm:5.7.0:*:*:*:*:*:*:* |
Mon, 03 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 27 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Churchcrm
Churchcrm churchcrm |
|
Metrics |
cvssV3_1
|
Fri, 22 Nov 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-04T16:40:25.956Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53438

Updated: 2024-11-27T16:53:29.858Z

Status : Analyzed
Published: 2024-11-22T17:15:10.857
Modified: 2025-03-28T16:39:27.213
Link: CVE-2024-53438

No data.