Blind SQL Injection Vulnerability in ChurchCRM Product by ChurchCRM
CVE-2024-25891

Currently unrated

Key Information:

Vendor

ChurchCRM

Status
Vendor
CVE Published:
21 February 2024

What is CVE-2024-25891?

The ChurchCRM product version 5.5.0 contains a Blind SQL Injection vulnerability within the FRBidSheets.php file. This vulnerability can be exploited by attackers through the manipulation of the CurrentFundraiser GET parameter, allowing for time-based SQL injection attacks. When successfully executed, attackers may gain unauthorized access to sensitive information stored in the database, leading to potential data breaches and compromise of the application's integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.