ChurchCRM是ChurchCRM开源的一个为教会打造的开源 CRM 系统。 ChurchCRM 5.13.0版本及之前版本存在安全漏洞,该漏洞源于newCountName参数未经适当清理就直接连接到 SQL 查询中。攻击者利用该漏洞可以操纵数据库查询并执行任意命令,从而可能导致数据泄露、修改或删除。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-1023.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论