CRITICAL🇵🇱 Wersja polska

CVE-2025-68112

CVSS 9.6v3.1pub. 2025-12-17upd. 2025-12-18

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise, administrative credential theft, and potential system takeover. The vulnerability enables attackers to extract sensitive member data, authentication credentials, and financial information from the church management system. Version 6.5.3 contains a patch for the issue.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-89 (SQL Injection) results from the lack of proper filtering or parameterization of input data passed to SQL queries in the Event Attendee Editor module. A logged-in user can craft malicious input data, which will be executed as part of an SQL query on the database server side. The mechanism does not require high privileges or interaction from other users, and its scope extends beyond the component where the error occurs (Scope: Changed).

Impact

An attacker can read or modify the entire database contents, including member personal data, authentication data (including administrator credentials), and financial information, which may lead to takeover of system control.

Mitigation & patch

ChurchCRM must be urgently updated to version 6.5.3, which contains a patch eliminating the described vulnerability. Details are available in the vendor references: https://github.com/ChurchCRM/CRM/security/advisories/GHSA-hxf4-3vhp-wqcq

Who is affected

ChurchCRM in versions earlier than 6.5.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Churchcrm

    APP
    Churchcrm
    < 6.5.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-39339CRITICAL9.1PL ✓same product

ChurchCRM — krytyczny auth bypass w API middleware

CVE-2026-39342CRITICAL9.4PL ✓same product

SQL Injection w ChurchCRM przez parametr searchwhat (QueryView.php)

CVE-2026-35573CRITICAL9.1PL ✓same product

ChurchCRM: Path Traversal i RCE przez funkcję przywracania kopii zapasowej

CVE-2026-39337CRITICAL10.0PL ✓same product

ChurchCRM: pre-auth RCE przez wstrzyknięcie kodu PHP w kreatorze instalacji

CVE-2025-68110CRITICAL9.9PL ✓same product

ChurchCRM: ujawnienie danych logowania do bazy danych w komunikacie błędu