EcclesiaCRM, a church management platform, contains a critical SQL injection vulnerability in versions prior to 8.0.0 affecting the query view functionality through the custom and value parameters in v2/templates/query/queryview.php. The vulnerability has been resolved in version 8.0.0 and later. This flaw allows attackers to execute arbitrary SQL commands against the application's database. The vulnerability carries a CVSS score of 9.8 (Critical) with a network-based attack vector requiring no authentication, low complexity, and no user interaction, resulting in complete compromise of confidentiality, integrity, and availability. The attack can be executed remotely by an unauthenticated threat actor without prerequisites, making it highly exploitable from a technical perspective. There is no evidence of active exploitation in the wild, with an EPSS score of 0.000310000 indicating very low probability of exploitation among disclosed vulnerabilities. The vulnerability is not listed in the Known Exploited Vulnerabilities catalog and has not generated significant community attention. Organizations running EcllesiaCRM versions prior to 8.0.0 should prioritize patching despite the low current exploitation likelihood, given the critical severity rating and ease of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0.0CPE matchmatch criteria | cpe:2.3:a:ecclesiacrm:ecclesiacrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.