GHSA-5q5x-wqxc-vv25CriticalCVSS 9.8
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in...
🔗 CVE IDs covered (1)
📋 Description
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2025-70150
- https://www.phpscriptsonline.com/product/membership-management-software
- https://youngkevinn.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete
- https://0x0bito.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete
- https://github.com/advisories/GHSA-5q5x-wqxc-vv25