Executive brief
CodeAstro Membership Management System 1.0 is vulnerable to a security flaw that could allow unauthorized individuals to access sensitive database information. The system, which is used to manage member records and subscriptions, fails to properly secure the membership renewal process. An attacker could exploit this to steal member data or other confidential information stored in the application's database.
Technical details
A SQL injection vulnerability exists in CodeAstro Membership Management System 1.0 within the 'renew.php' component. The application fails to sufficiently sanitize or parameterize the 'membershipType' input parameter before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the vulnerable endpoint. Successful exploitation allows the attacker to execute arbitrary SQL commands, potentially leading to the unauthorized extraction of sensitive data from the underlying database. No patches are currently documented in the advisory.
Affected products
- CodeAstro Membership Management System 1.0
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory