A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query without proper sanitization, making it susceptible to SQL injection attacks. An attacker can manipulate the query, potentially leading to data exfiltration, modification, or deletion.  Please note that this vulnerability requires Administrator privileges.
History

Tue, 25 Feb 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Churchcrm
Churchcrm churchcrm
CPEs cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
Vendors & Products Churchcrm
Churchcrm churchcrm
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 19 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query without proper sanitization, making it susceptible to SQL injection attacks. An attacker can manipulate the query, potentially leading to data exfiltration, modification, or deletion.  Please note that this vulnerability requires Administrator privileges.
Title SQL Injection in ChurchCRM EID Parameter via EditEventAttendees.php
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/AU:Y/R:U/V:C/RE:H/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2025-02-19T15:03:53.926Z

Reserved: 2025-02-08T04:11:55.409Z

Link: CVE-2025-1133

cve-icon Vulnrichment

Updated: 2025-02-19T15:03:49.148Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-19T09:15:10.550

Modified: 2025-02-25T21:26:57.793

Link: CVE-2025-1133

cve-icon Redhat

No data.