vendor:
ChurchCRM
by:
Iyaad Luqman K
7.4
CVSS
HIGH
SQL Injection
89
CWE
Product Name: ChurchCRM
Affected Version From: 4.5.2001
Affected Version To: 4.5.2003
Patch Exists: YES
Related CWE: CVE-2023-24685
CPE: a:churchcrm:churchcrm:4.5.3
Platforms Tested: Windows, Linux
2023
ChurchCRM 4.5.3 – Authenticated SQL Injection
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module. After Logging in, a GET request can be sent to the EventAttendance.php page with the Event parameter set to a malicious SQL query. The response will dump the usr_Username and usr_Password from the database.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in a SQL query.