CVE-2025-1134
19.02.2025, 09:15
A vulnerability exists in ChurchCRM5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injectionvulnerability in the DonatedItemEditorfunctionality. The CurrentFundraiserparameter is directly concatenated into an SQL query without sufficient sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion. Please note that this vulnerability requires Administrator privileges.
Vendor | Product | Version |
---|---|---|
churchcrm | churchcrm | 𝑥 ≤ 5.13.0 |
𝑥
= Vulnerable software versions