CVE-2022-31325
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
- Affected products
- Churchcrm
- Churchcrm
- = 4.4.5
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 5.2% (92th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2022-06-08
CVE-2022-31325 at NVD
4 known exploits for CVE-2022-31325
Proof-of-concept code and exploit modules indexed by Sploitus