Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66395

Опубликовано: 17 дек. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the src/ListEvents.php file. When filtering events by type, the WhichType POST parameter is not properly sanitized or type-casted before being used in multiple SQL queries. This allows any authenticated user to execute arbitrary SQL commands, including time-based blind SQL injection attacks. Any authenticated user, regardless of their privilege level, can execute arbitrary queries on the database. This could allow them to exfiltrate, modify, or delete any data in the database, including user credentials, financial data, and personal information, leading to a full compromise of the application's data. Version 6.5.3 fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
Версия до 6.5.3 (исключая)

EPSS

Процентиль: 11%
0.00037
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

EPSS

Процентиль: 11%
0.00037
Низкий

8.8 High

CVSS3

Дефекты

CWE-89