PT-2025-51357 · Churchcrm · Churchcrm

Xy20130630

·

Published

2025-12-16

·

Updated

2025-12-21

·

CVE-2025-67751

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.0
Description A SQL injection issue exists in the EventEditor.php file of ChurchCRM. The EN tyid POST parameter, used when creating a new event and selecting an event type, is not properly sanitized. This allows a user with event management permissions (isAddEvent) to execute arbitrary SQL queries.
Recommendations Update to version 6.5.0 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-67751
GHSA-WXCC-GVFV-56FG

Affected Products

Churchcrm