SQL Injection Vulnerability in ChurchCRM by ChurchHub
CVE-2025-1135
9.3CRITICAL
What is CVE-2025-1135?
A security flaw in ChurchCRM versions 5.13.0 and earlier permits an attacker with Administrator privileges to perform a boolean-based and time-based blind SQL Injection. This arises from improper handling of the CurrentFundraiser parameter, which is concatenated directly into SQL queries without adequate sanitization. As a result, attackers may manipulate database operations leading to unauthorized data access, exfiltration, modification, or deletion, posing significant risks to sensitive information.
Affected Version(s)
ChurchCRM ChurchCRM 5.13.0 and prior