Логотип exploitDog
bind:CVE-2024-53438
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-53438

Количество 2

Количество 2

nvd логотип

CVE-2024-53438

около 1 года назад

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gr5x-8j97-qq23

около 1 года назад

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-53438

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-gr5x-8j97-qq23

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

CVSS3: 9.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу