PT-2026-20465 · Unknown · Codeastro Membership Management System

CVE-2025-70148

·

Publicado

2026-02-18

·

Atualizado

2026-02-24

CVSS v3.1

7.5

Alta

VetorAC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions CodeAstro Membership Management System version 1.0
Description The application lacks proper authentication and authorization in the print membership card.php file. This allows unauthenticated attackers to access membership card data belonging to any user by directly requesting the file with a manipulated id parameter. This results in an insecure direct object reference (IDOR).
Recommendations Implement proper authentication and authorization checks in the print membership card.php file to ensure that only authorized users can access membership card data. Validate the id parameter to prevent direct object reference vulnerabilities.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-70148

Produtos afetados

Codeastro Membership Management System