CVE-2023-29842 Information

Description

ChirchCRm 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

Reference

https://github.com/ChurchCRM/CRM https://github.com/arvandy/CVE/blob/main/CVE-2023-29842/CVE-2023-29842.py https://github.com/arvandy/CVE/blob/main/CVE-2023-29842/CVE-2023-29842.md

Share on: