Blind SQL Injection Vulnerability in ChurchCRM Product by ChurchCRM
CVE-2024-25891
Currently unrated
What is CVE-2024-25891?
The ChurchCRM product version 5.5.0 contains a Blind SQL Injection vulnerability within the FRBidSheets.php file. This vulnerability can be exploited by attackers through the manipulation of the CurrentFundraiser GET parameter, allowing for time-based SQL injection attacks. When successfully executed, attackers may gain unauthorized access to sensitive information stored in the database, leading to potential data breaches and compromise of the application's integrity.