Cyber Posture

CVE-2025-1133

HighPublic PoC

Published: 19 February 2025

Published
19 February 2025
Modified
25 February 2025
KEV Added
Patch
CVSS Score 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0018 38.9th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.

Security Summary

CVE-2025-1133 is a boolean-based blind SQL injection vulnerability affecting ChurchCRM versions 5.13.0 and prior. The issue exists in the EditEventAttendees functionality, where the EID parameter is directly concatenated into an SQL query without proper sanitization, enabling attackers to execute arbitrary SQL queries.

This vulnerability requires Administrator privileges for exploitation and can be triggered over the network with low attack complexity and no user interaction. A successful attack allows data exfiltration, modification, or deletion, with high impacts on confidentiality, integrity, and availability, as reflected in its CVSS v3.1 base score of 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Mitigation details are available in the referenced advisory at https://github.com/ChurchCRM/CRM/issues/7252.

Details

CWE(s)
CWE-89

Affected Products

churchcrm
churchcrm
≤ 5.13.0

MITRE ATT&CK Enterprise Techniques

T1213.006 Databases Collection
Adversaries may leverage databases to mine valuable information.
T1485 Data Destruction Impact
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
T1565.001 Stored Data Manipulation Impact
Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.
Why these techniques?

The SQL injection vulnerability in ChurchCRM enables arbitrary SQL query execution with admin privileges, facilitating database data collection (T1213.006), stored data manipulation via updates/inserts (T1565.001), and data destruction via deletes (T1485).

References