SQL Injection Vulnerability in ChurchCRM by ChurchCRM
CVE-2025-1133
9.3CRITICAL
What is CVE-2025-1133?
A vulnerability has been identified in ChurchCRM versions up to 5.13.0 that could allow attackers to execute arbitrary SQL queries via the EditEventAttendees functionality. The EID parameter is directly added into the SQL query without proper input sanitization, making it vulnerable to exploitation through boolean-based blind SQL injection. This weakness can permit attackers with Administrator privileges to manipulate the database, potentially leading to unauthorized access, data exfiltration, modification, or even deletion of critical information.
Affected Version(s)
ChurchCRM ChurchCRM 5.13.0 and prior