Executive brief
CodeAstro Membership Management System 1.0 is affected by a security flaw that allows unauthorized access to its underlying database. This system is typically used to manage member records and financial reports. By exploiting this vulnerability, an attacker could potentially view, modify, or delete sensitive member data and financial information, leading to data theft or operational disruption.
Technical details
A SQL injection vulnerability exists in CodeAstro Membership Management System 1.0 within the reporting modules. The application fails to properly sanitize the 'fromDate' parameter in both 'report.php' and 'revenue_report.php' before using it in a database query. A remote attacker can exploit this by sending specially crafted HTTP requests containing SQL commands. Successful exploitation allows the attacker to bypass authentication, extract sensitive information from the database, or potentially gain administrative control over the application environment. As of the advisory date, no official patch has been confirmed.
Affected products
- CodeAstro Membership Management System 1.0
Timeline
- 2026-07-30: disclosed: CVE published by MITRE/NVD