A vulnerability classified as critical has been found in ChurchCRM 5.5.0. Affected is an unknown function of the file ConfirmReport.php of the component GET Parameter Handler. The manipulation of the argument familyId leads to sql injection.
This vulnerability is traded as CVE-2024-25892. The attack can only be done within the local network. There is no exploit available.