What is CVE-2025-69936?
A SQL Injection vulnerability was found in the `/edit_member.php` file of CodeAstro Membership Management System 1.0. The flaw allows unauthorized database access via the `id` parameter. Administrators should immediately implement input validation and apply the patch.
Azərbaycanca: CodeAstro Membership Management System 1.0 proqramının `/edit_member.php` faylında SQL Injection zəifliyi aşkarlanıb. Bu, `id` parametri vasitəsilə məlumat bazasına icazəsiz giriş əldə etməyə şərait yaradır. İnzibatçılar dərhal giriş yoxlamalarını tətbiq etməli və düzəliş paketini quraşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: CodeAstro
FAQ2
In which file was the SQL Injection vulnerability found in CodeAstro Membership Management System 1.0?
The vulnerability was found in the `/edit_member.php` file.
How can an attacker exploit CVE-2025-69936 to interfere with the database?
An attacker can gain unauthorized database access by performing SQL Injection via the `id` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.