SQL Injection Vulnerability in CodeAstro Membership Management System
CVE-2024-25866
8.8HIGH
What is CVE-2024-25866?
A SQL Injection vulnerability exists in the CodeAstro Membership Management System for PHP v.1.0, where remote attackers can exploit the email parameter in the index.php component. This flaw enables malicious actors to execute arbitrary SQL commands, potentially allowing unauthorized access to sensitive data and manipulation of the underlying database. This type of vulnerability emphasizes the need for robust input validation and regular security assessments.
