CVE-2025-1023

A vulnerability exists in ChurchCRM5.13.0 and priorthat allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injectionvulnerability in the EditEventTypesfunctionality. The newCountNameparameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GridwareCNA
---
---
CISA-ADPADP
---
---