Vulnerabilities
Vulnerable Software
Churchcrm:  >> Churchcrm  >> 5.5.0  Security Vulnerabilities
ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVSS Score
9.1
EPSS Score
0.003
Published
2024-02-21
ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
CVSS Score
9.8
EPSS Score
0.002
Published
2024-02-21
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php
CVSS Score
6.1
EPSS Score
0.001
Published
2024-02-21
ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-02-21
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVSS Score
9.8
EPSS Score
0.123
Published
2024-02-21
A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event Sermon field in EventEditor.php.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-02-21


Contact Us

Shodan ® - All rights reserved