What is CVE-2025-69934?
A critical SQL Injection vulnerability has been identified in CodeAstro Membership Management System 1.0. This flaw allows remote code execution via the 'id' parameter in /delete_members.php. Users must urgently apply patches from the vendor.
Azərbaycanca: CodeAstro Membership Management System 1.0-da kritik SQL Injection zəifliyi aşkar edilib. Bu boşluq /delete_members.php faylındakı 'id' parametri vasitəsilə uzaqdan kod icrasına imkan verir. İstifadəçilər təcili olaraq istehsalçıdan yamaq tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: CodeAstro
FAQ2
Which version of CodeAstro Membership Management System is affected by CVE-2025-69934?
This vulnerability affects version 1.0 of CodeAstro Membership Management System.
What can an attacker achieve by exploiting the SQL Injection vulnerability CVE-2025-69934?
Through this SQL Injection vulnerability, an attacker can achieve remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.