📦

membership_management_system

Vendor: codeastro

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 4 Remote Access
Total CVEs 23 Total Indexed
Avg. EPSS 1.54% Exploit Prob.
Latest CVE CVE-2025-70150 Feb 18

Security Vulnerability Index

Page 1 / 3
9.8 CVSS

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

EPSS: 0.57%
7.5 CVSS

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).

EPSS: 0.39%
9.8 CVSS
CVE-2025-70149
Exploit Found

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

EPSS: 0.35%
6.9 CVSS

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS: 0.47%
5.4 CVSS

CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php

EPSS: 0.30%
5.4 CVSS

CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.

EPSS: 0.27%
8.6 CVSS

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.

EPSS: 0.44%
7.5 CVSS

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.

EPSS: 0.50%
6.1 CVSS

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

EPSS: 0.33%
5.4 CVSS

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

EPSS: 0.27%