What is CVE-2025-69937?
This SQL Injection vulnerability affects CodeAstro Membership Management System 1.0 via the 'id' parameter in the edit_type.php endpoint. Attackers may manipulate database queries, so input validation and parameter sanitization should be applied immediately.
Azərbaycanca: Bu SQL Injection zəifliyi CodeAstro Membership Management System 1.0 proqramının edit_type.php faylında, 'id' parametri vasitəsilə aşkarlanıb. Təcavüzkar verilənlər bazasına müdaxilə edə bilər, ona görə də dərhal giriş yoxlanışı və parametr təmizlənməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: CodeAstro
FAQ2
In which file of the CodeAstro Membership Management System is the SQL Injection vulnerability located?
The vulnerability is found in the 'edit_type.php' file.
How can an attacker exploit CVE-2025-69937?
An attacker can manipulate database queries by performing SQL Injection through the 'id' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.