CVE-2025-70150

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

Scoring

Severity
CRITICAL
CVSS base score
9.8
CVSS vector
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
EPSS probability
0.65%
Published
2026-02-18
Last modified
2026-09-08

Affected products

Markdown version · Browse all CVEs