Security Advisory

CVE-2025-66313

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-01 22:13:20
Last updated 2025-12-02 15:45:17
Assigner GitHub_M
State PUBLISHED

Description

ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value is incorporated into a SQL query without proper parameterization. The issue allows data exfiltration and modification via blind techniques.