CVE-2025-70148 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access m…
High CVSS: 7.5

CVE-2025-70148

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).
Vendor
Codeastro
Product
Membership Management System
CWE
CWE-862
Yayın Tarihi
2026-02-18 18:24:19
Güncelleme
2026-02-20 13:55:58
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar