A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands. Please note that the vulnerability requires Administrator permissions. This flaw can potentially allow attackers to delay the response, indicating the presence of an SQL injection vulnerability. While it is a time-based blind injection, it can be exploited to gain insights into the underlying database, and with further exploitation, sensitive data could be retrieved.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/ChurchCRM/CRM/issues/7251 |
|
History
Tue, 25 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
| CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Churchcrm
Churchcrm churchcrm |
|
| Metrics |
cvssV3_1
|
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Feb 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to inject malicious SQL commands. Please note that the vulnerability requires Administrator permissions. This flaw can potentially allow attackers to delay the response, indicating the presence of an SQL injection vulnerability. While it is a time-based blind injection, it can be exploited to gain insights into the underlying database, and with further exploitation, sensitive data could be retrieved. | |
| Title | SQL Injection in ChurchCRM EN_tyid Parameter via EditEventAttendees.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Gridware
Published: 2025-02-19T08:47:13.370Z
Updated: 2025-02-19T15:05:57.942Z
Reserved: 2025-02-08T04:11:44.370Z
Link: CVE-2025-1132
Updated: 2025-02-19T15:05:54.192Z
Status : Analyzed
Published: 2025-02-19T09:15:10.417
Modified: 2025-02-25T21:48:03.217
Link: CVE-2025-1132
No data.