What is CVE-2025-69935?
A SQL Injection vulnerability was identified in CodeAstro Membership Management System 1.0, specifically in the report.php file via the fromDate parameter. This allows attackers to execute unauthorized database queries. Users are advised to immediately implement input validation.
Azərbaycanca: CodeAstro Membership Management System 1.0 proqramının report.php səhifəsində fromDate parametri vasitəsilə SQL Injection zəifliyi aşkar edilib. Bu, təcavüzkara məlumat bazasına icazəsiz sorğular göndərməyə imkan verir. İstifadəçilərə dərhal giriş validasiyasını tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: CodeAstro
FAQ2
Which version of CodeAstro Membership Management System is affected by CVE-2025-69935?
CVE-2025-69935 affects version 1.0 of CodeAstro Membership Management System.
Through which file and parameter is the SQL Injection vulnerability in CVE-2025-69935 exploited?
The vulnerability is exploited via the fromDate parameter in the report.php file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.