CVE-2025-1023
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 18, 2025
Updated: Feb 21, 2025
CWE ID 89
Summary
CVE-2025-1023 is a vulnerability affecting ChurchCRM 5.13.0 and earlier versions. It allows unauthorized users to execute arbitrary SQL queries through the EditEventTypes functionality, due to a time-based blind SQL injection flaw. The newCountName parameter, which is directly concatenated into an SQL query without proper sanitization, can be manipulated by attackers to modify, delete, or exfiltrate data from the database, potentially causing significant damage.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Churchcrm