SQL Injection Vulnerability in ChurchCRM Affects Data Integrity
CVE-2025-66395
What is CVE-2025-66395?
ChurchCRM, an open-source church management system, is vulnerable to SQL injection due to improper sanitization of user input in the WhichType POST parameter in the src/ListEvents.php file. This flaw allows any authenticated user to leverage the vulnerability to execute arbitrary SQL commands. Consequently, an attacker can potentially exfiltrate, alter, or delete sensitive data within the database, including user credentials and financial information. The issue affects all versions prior to 6.5.3, which includes a patch to resolve this critical security gap.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CRM < 6.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
