CVE-2025-7929 is a critical SQL injection vulnerability affecting version 1.0 of the code-projects Church Donation System. Specifically, an attacker can manipulate the 'fname' argument within the /members/edit_Members.php file to inject malicious SQL queries. This vulnerability carries a CVSS score of 9.8 (Critical), indicating it can be exploited remotely without authentication or user interaction, leading to full compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 95/100. While there is no evidence of active exploitation in the wild (KEV: No), the exploit has been publicly disclosed. The vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:carmelo:church_donation_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.