High severity7.2NVD Advisory· Published Feb 9, 2023· Updated Jun 17, 2026
CVE-2023-24685
CVE-2023-24685
Description
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/blakduk/Advisories/blob/main/ChurchCRM/README.mdnvdExploitThird Party Advisory
- churchcrm.ionvdProduct
- packetstormsecurity.com/files/172047/ChurchCRM-4.5.3-SQL-Injection.htmlnvd
- github.com/ChurchCRM/CRM/issues/6441nvd
News mentions
0No linked articles in our index yet.