8.8
CVSSv3

CVE-2023-29842

Published: 04/05/2023 Updated: 26/10/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

churchcrm churchcrm 4.5.4

Exploits

ChurchCRM version 454 suffers from a remote authenticated blind SQL injection vulnerability ...