CVE-2025-70148
18.02.2026, 18:24
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| codeastro | membership_management_system | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration