CVE-2025-66313
01.12.2025, 23:15
ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value is incorporated into a SQL query without proper parameterization. The issue allows data exfiltration and modification via blind techniques.
| Vendor | Product | Version |
|---|---|---|
| churchcrm | churchcrm | 𝑥 ≤ 6.2.0 |
𝑥
= Vulnerable software versions