IDOR Vulnerability in CodeAstro Membership Management System
CVE-2025-70148
7.5HIGH
What is CVE-2025-70148?
A critical security flaw in the CodeAstro Membership Management System 1.0 where missing authentication and authorization in print_membership_card.php permits unauthorized attackers to access sensitive membership card data. This can be exploited by manipulating the 'id' parameter in requests, allowing attackers to retrieve data belonging to arbitrary users, thereby exposing the system to significant data leakage risks.
