Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-1133

Опубликовано: 19 фев. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query without proper sanitization, making it susceptible to SQL injection attacks. An attacker can manipulate the query, potentially leading to data exfiltration, modification, or deletion.  Please note that this vulnerability requires Administrator privileges.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
Версия до 5.13.0 (включая)

EPSS

Процентиль: 37%
0.00158
Низкий

7.2 High

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.2
github
12 месяцев назад

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query without proper sanitization, making it susceptible to SQL injection attacks. An attacker can manipulate the query, potentially leading to data exfiltration, modification, or deletion.  Please note that this vulnerability requires Administrator privileges.

EPSS

Процентиль: 37%
0.00158
Низкий

7.2 High

CVSS3

Дефекты

CWE-89
CWE-89