CVE-2025-70150
- EPSS 0.31%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 23.02.2026 16:13:10
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
CVE-2025-70148
- EPSS 0.09%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 20.02.2026 13:55:58
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter...
CVE-2025-70149
- EPSS 0.04%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 23.02.2026 16:13:40
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
CVE-2025-3998
- EPSS 0.2%
- Veröffentlicht 28.04.2025 03:00:05
- Zuletzt bearbeitet 14.05.2025 19:49:55
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiate...
CVE-2024-48709
- EPSS 0.18%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 31.03.2025 17:58:22
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
CVE-2024-46236
- EPSS 0.21%
- Veröffentlicht 21.10.2024 19:15:03
- Zuletzt bearbeitet 31.03.2025 17:49:13
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
CVE-2024-46472
- EPSS 0.06%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 31.03.2025 19:02:48
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
CVE-2024-46471
- EPSS 0.25%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 31.03.2025 19:07:09
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.
CVE-2024-46470
- EPSS 0.19%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 31.03.2025 19:19:17
Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.
CVE-2024-45528
- EPSS 0.16%
- Veröffentlicht 02.09.2024 05:15:17
- Zuletzt bearbeitet 31.03.2025 18:53:04
CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.