Time-Based Blind SQL Injection in ChurchCRM by ChurchCRM
CVE-2025-1132

9.3CRITICAL

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
19 February 2025

What is CVE-2025-1132?

A time-based blind SQL Injection vulnerability exists in ChurchCRM versions 5.13.0 and earlier, specifically in the EditEventAttendees.php file when handling the EN_tyid parameter. This parameter is passed into an SQL query without adequate sanitization, allowing malicious actors to inject harmful SQL commands. Although exploitation of this vulnerability necessitates Administrator permissions, the flaw could allow attackers to manipulate response timings to confirm the presence of SQL injection vulnerabilities. This technique can potentially enable the retrieval of sensitive data from the underlying database by exploiting the flaw further.

Affected Version(s)

ChurchCRM ChurchCRM 5.13.0 and prior

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael McInerney
.