SQL Injection Vulnerability in CodeAstro Membership Management System
CVE-2025-69935
9.8CRITICAL
What is CVE-2025-69935?
The CodeAstro Membership Management System version 1.0 is susceptible to SQL Injection attacks through vulnerable endpoints report.php and revenue_report.php. This vulnerability can be exploited via the fromDate parameter, allowing an attacker to manipulate database queries. Exploiters could potentially gain unauthorized access to sensitive information or execute arbitrary SQL commands, compromising the integrity and confidentiality of the system's data.
