Time-Based Blind SQL Injection in ChurchCRM by ChurchCRM
CVE-2025-1132
9.3CRITICAL
What is CVE-2025-1132?
A time-based blind SQL Injection vulnerability exists in ChurchCRM versions 5.13.0 and earlier, specifically in the EditEventAttendees.php file when handling the EN_tyid parameter. This parameter is passed into an SQL query without adequate sanitization, allowing malicious actors to inject harmful SQL commands. Although exploitation of this vulnerability necessitates Administrator permissions, the flaw could allow attackers to manipulate response timings to confirm the presence of SQL injection vulnerabilities. This technique can potentially enable the retrieval of sensitive data from the underlying database by exploiting the flaw further.
Affected Version(s)
ChurchCRM ChurchCRM 5.13.0 and prior