PT-2023-19736 · Churchcrm · Churchcrm
Blakduk
·
Publicado
2023-02-09
·
Atualizado
2025-03-24
·
CVE-2023-24685
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions 4.5.3 and below
Description
A SQL injection issue was found in the Event Attendance reports module, specifically via the
Event parameter.Recommendations
For ChurchCRM versions 4.5.3 and below, update to a version above 4.5.3 to resolve the issue.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Churchcrm