What is CVE-2025-69933?
A SQL Injection vulnerability exists in the 'id' parameter of /memberProfile.php in CodeAstro Membership Management System 1.0. This allows an attacker to send unauthorized queries to the database. Input sanitization and parameterized queries should be implemented for security.
Azərbaycanca: CodeAstro Üzvlük İdarəetmə Sistemi 1.0-da /memberProfile.php faylındakı 'id' parametrində SQL Injection zəifliyi aşkar edilib. Bu, hücumçuya verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Təhlükəsizlik üçün daxiletmələrin təmizlənməsi və parametrləşdirilmiş sorğulardan istifadə edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: CodeAstro
FAQ2
Where is the SQL Injection vulnerability located in CodeAstro Membership Management System 1.0?
The vulnerability exists in the 'id' parameter of the /memberProfile.php file.
What does the SQL Injection vulnerability in CodeAstro Membership Management System 1.0 allow an attacker to do?
It allows an attacker to send unauthorized queries to the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.