Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51967 | EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 29 Mar 2025 02:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:churchcrm:churchcrm:5.7.0:*:*:*:*:*:*:* |
Tue, 04 Feb 2025 03:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 28 Nov 2024 02:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Churchcrm
Churchcrm churchcrm |
|
| Metrics |
cvssV3_1
|
Sat, 23 Nov 2024 01:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-04T16:40:25.956Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53438
Updated: 2024-11-27T16:53:29.858Z
Status : Analyzed
Published: 2024-11-22T17:15:10.857
Modified: 2025-03-28T16:39:27.213
Link: CVE-2024-53438
No data.
OpenCVE Enrichment
No data.
EUVD