CVE-2023-29842: Churchcrm
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.
Affected products
- Churchcrm Churchcrm: version 4.5.4 only
Published 2023-05-04. Last modified 2026-06-17.