Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr5x-8j97-qq23

Опубликовано: 22 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

EPSS

Процентиль: 43%
0.0021
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

EPSS

Процентиль: 43%
0.0021
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89