EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/ChurchCRM/CRM/issues/6988 |
History
Wed, 27 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Churchcrm
Churchcrm churchcrm |
|
Metrics |
cvssV3_1
|
Fri, 22 Nov 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-22T00:00:00
Updated: 2024-11-27T16:53:44.747Z
Reserved: 2024-11-20T00:00:00
Link: CVE-2024-53438
Vulnrichment
Updated: 2024-11-27T16:53:29.858Z
NVD
Status : Awaiting Analysis
Published: 2024-11-22T17:15:10.857
Modified: 2024-11-27T17:15:14.647
Link: CVE-2024-53438
Redhat
No data.