Junglewise Threat Intelligence

CVE-2026-36387: CODEASTRO Membership Management System RCE in add_members.php

CVE-2026-36387 · Severity: medium · CVSS 6.5 · Published 2026-05-07

Technologies: CodeAstro Membership Management System. Vendors: CodeAstro.

Executive brief

A security vulnerability exists in the CODEASTRO Membership Management System, a tool used for managing member records and profiles. An attacker can exploit the member registration process to upload malicious files to the server. If successful, this allows the attacker to take control of the server, access sensitive member data, or disrupt business operations.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in CODEASTRO Membership Management System v1.0 within the 'add_members.php' component. The application fails to properly validate or sanitize file extensions and content types for the 'Member Photo' upload field. A remote attacker can intercept the upload request and replace a legitimate image file with a PHP shell. Once uploaded to the '/uploads/member_photos/' directory, the attacker can execute arbitrary system commands by accessing the file directly via a web browser. While the CVSS provided by CISA-ADP is 6.5, the researcher notes the impact allows for full server compromise.

Affected products

  • CODEASTRO Membership Management System 1.0

Timeline

  • 2026-02: disclosed: Discovered by Raneisha Justin
  • 2026-05-07: advisory: NVD Published Date

References

Related threats