SQL Injection Vulnerability in ChurchCRM by ChurchHub
CVE-2025-1135

9.3CRITICAL

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
19 February 2025

What is CVE-2025-1135?

A security flaw in ChurchCRM versions 5.13.0 and earlier permits an attacker with Administrator privileges to perform a boolean-based and time-based blind SQL Injection. This arises from improper handling of the CurrentFundraiser parameter, which is concatenated directly into SQL queries without adequate sanitization. As a result, attackers may manipulate database operations leading to unauthorized data access, exfiltration, modification, or deletion, posing significant risks to sensitive information.

Affected Version(s)

ChurchCRM ChurchCRM 5.13.0 and prior

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael McInerney
.