Impact
A blind SQL injection exists in the PropertyTypeEditor.php endpoint for authenticated users with the isMenuOptionsEnabled role. The flaw allows injection of arbitrary SQL through the Name and Description parameters, enabling attackers to read sensitive information from the database and modify its contents. The injection is blind, so detection may be delayed, but the risk of data exfiltration and corruption is significant.
Affected Systems
The vulnerability affects ChurchCRM installations running versions prior to 7.1.0. All stable releases before 7.1.0 expose the PropertyTypeEditor.php endpoint and are susceptible when users have the isMenuOptionsEnabled role. The issue was addressed in version 7.1.0.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and an EPSS below 1% suggests exploitation probability is low but not negligible. The CVE is not listed in the KEV catalog. Attackers would need authenticated access with the isMenuOptionsEnabled role, making the attack vector internal or through privileged user compromise. Once exploited, attackers could retrieve or alter critical church data.
OpenCVE Enrichment