CVE-2025-70150: Critical severity Codeastro Membership Management System vulnerability
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in deletemembers.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70150?
CVE-2025-70150 is considered a critical vulnerability due to its potential for unauthenticated attackers to delete member records.
How do I fix CVE-2025-70150?
To fix CVE-2025-70150, implement authentication controls for the delete_members.php script to ensure only authorized users can delete member records.
What are the consequences of exploiting CVE-2025-70150?
Exploiting CVE-2025-70150 allows attackers to delete arbitrary member data, leading to potential loss of critical information and disrupting service.
Which software is affected by CVE-2025-70150?
CVE-2025-70150 affects CodeAstro Membership Management System version 1.0.
Can CVE-2025-70150 be exploited remotely?
Yes, CVE-2025-70150 can be exploited remotely by unauthenticated users through the id parameter.