CVE-2025-70149

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codeastro:membership_management_system:1.0:*:*:*:*:*:*:*

History

23 Feb 2026, 16:13

Type Values Removed Values Added
First Time Codeastro membership Management System
Codeastro
Summary
  • (es) CodeAstro Membership Management System 1.0 es vulnerable a inyección SQL en print_membership_card.php a través del parámetro ID.
CPE cpe:2.3:a:codeastro:membership_management_system:1.0:*:*:*:*:*:*:*
References () https://www.phpscriptsonline.com/product/membership-management-software - () https://www.phpscriptsonline.com/product/membership-management-software - Product
References () https://youngkevinn.github.io/posts/CVE-2025-70149-Membership-SQLi/ - () https://youngkevinn.github.io/posts/CVE-2025-70149-Membership-SQLi/ - Exploit, Mitigation, Third Party Advisory

18 Feb 2026, 19:21

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

18 Feb 2026, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 17:21

Updated : 2026-02-23 16:13


NVD link : CVE-2025-70149

Mitre link : CVE-2025-70149

CVE.ORG link : CVE-2025-70149


JSON object : View

Products Affected

codeastro

  • membership_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')