PT-2025-51357 · Churchcrm · Churchcrm

·

CVE-2025-67751

·

Published

2025-12-16

·

Updated

2025-12-21

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.0
Description A SQL injection issue exists in the EventEditor.php file of ChurchCRM. The EN tyid POST parameter, used when creating a new event and selecting an event type, is not properly sanitized. This allows a user with event management permissions (isAddEvent) to execute arbitrary SQL queries.
Recommendations Update to version 6.5.0 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67751
GHSA-WXCC-GVFV-56FG

Affected Products

Churchcrm