CVE-2025-70148: High severity Codeastro Membership Management System vulnerability
Missing authentication and authorization in printmembershipcard.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70148?
CVE-2025-70148 is considered a high severity vulnerability due to the potential for unauthorized access to sensitive user data.
How do I fix CVE-2025-70148?
To fix CVE-2025-70148, implement proper authentication and authorization checks before processing requests to print_membership_card.php.
What are the implications of CVE-2025-70148?
The implications of CVE-2025-70148 include unauthorized exposure of membership card data, leading to potential identity theft or fraud.
Who is affected by CVE-2025-70148?
CVE-2025-70148 affects users of CodeAstro Membership Management System 1.0 that have not secured their membership card access.
Can CVE-2025-70148 be exploited remotely?
Yes, CVE-2025-70148 can be exploited remotely by unauthenticated attackers through manipulated requests.