7.2
CVSSv3

CVE-2023-24685

Published: 09/02/2023 Updated: 27/04/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

ChurchCRM v4.5.3 and below exists to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

churchcrm churchcrm

Exploits

ChurchCRM versions 453 and below suffer from a remote SQL injection vulnerability ...