CVE-2025-70150

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codeastro:membership_management_system:1.0:*:*:*:*:*:*:*

History

23 Feb 2026, 16:13

Type Values Removed Values Added
First Time Codeastro membership Management System
Codeastro
References () https://www.phpscriptsonline.com/product/membership-management-software - () https://www.phpscriptsonline.com/product/membership-management-software - Product
References () https://youngkevinn.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete/ - () https://youngkevinn.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete/ - Exploit, Mitigation, Third Party Advisory
CPE cpe:2.3:a:codeastro:membership_management_system:1.0:*:*:*:*:*:*:*
Summary
  • (es) El Sistema de Gestión de Membresías CodeAstro 1.0 contiene una vulnerabilidad de autenticación faltante en delete_members.php que permite a atacantes no autenticados eliminar registros de miembros arbitrarios a través del parámetro id.

18 Feb 2026, 18:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 18:24

Updated : 2026-02-23 16:13


NVD link : CVE-2025-70150

Mitre link : CVE-2025-70150

CVE.ORG link : CVE-2025-70150


JSON object : View

Products Affected

codeastro

  • membership_management_system
CWE
CWE-862

Missing Authorization