What is CVE-2025-69938?
A SQL Injection vulnerability was discovered in CodeAstro Membership Management System 1.0, affecting `renew.php` via the `membershipType` parameter. This could allow attackers unauthorized access to the database. Users should update their systems immediately and validate input parameters.
Azərbaycanca: CodeAstro Membership Management System 1.0-da `renew.php` faylında `membershipType` parametri vasitəsilə SQL Injection zəifliyi aşkarlanıb. Bu, təcavüzkara verilənlər bazasına icazəsiz giriş əldə etməyə imkan verə bilər. İstifadəçilər təcili olaraq sistemlərini yeniləməli və giriş məlumatlarını yoxlamalıdırlar.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: CodeAstro
FAQ2
In which file of CodeAstro Membership Management System does the CVE-2025-69938 SQL Injection vulnerability exist?
The vulnerability exists in the `renew.php` file.
Which version is affected by CVE-2025-69938?
The vulnerability affects CodeAstro Membership Management System version 1.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.