SQL Injection Vulnerability in ChurchCRM Affecting Multiple Versions
CVE-2025-1023
9.3CRITICAL
What is CVE-2025-1023?
A SQL injection vulnerability in ChurchCRM allows unauthenticated users to exploit the EditEventTypes functionality, particularly through the newCountName parameter. By inserting malicious code into the SQL query, an attacker can manipulate the application's database, leading to unauthorized access, loss of sensitive information, or modification and deletion of crucial data. Proper input validation and sanitization measures are essential to mitigate this risk and protect user data.
Affected Version(s)
ChurchCRM ChurchCRM 5.13.0 and prior