A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands. Please note that the vulnerability requires Administrator permissions. This flaw can potentially allow attackers to delay the response, indicating the presence of an SQL injection vulnerability. While it is a time-based blind injection, it can be exploited to gain insights into the underlying database, and with further exploitation, sensitive data could be retrieved.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/ChurchCRM/CRM/issues/7251 |
![]() ![]() |
History
Tue, 25 Feb 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Churchcrm
Churchcrm churchcrm |
|
Metrics |
cvssV3_1
|
Wed, 19 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Feb 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands. Please note that the vulnerability requires Administrator permissions. This flaw can potentially allow attackers to delay the response, indicating the presence of an SQL injection vulnerability. While it is a time-based blind injection, it can be exploited to gain insights into the underlying database, and with further exploitation, sensitive data could be retrieved. | |
Title | SQL Injection in ChurchCRM EN_tyid Parameter via EditEventAttendees.php | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Gridware
Published:
Updated: 2025-02-19T15:05:57.942Z
Reserved: 2025-02-08T04:11:44.370Z
Link: CVE-2025-1132

Updated: 2025-02-19T15:05:54.192Z

Status : Analyzed
Published: 2025-02-19T09:15:10.417
Modified: 2025-02-25T21:48:03.217
Link: CVE-2025-1132

No data.