VYPR

Membership Management System in PHP

by Codeastro

CVEs (3)

  • CVE-2024-25869HigFeb 28, 2024
    risk 0.59cvss 8.8epss 0.19

    An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.

  • CVE-2024-25866HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.

  • CVE-2024-45528MedSep 2, 2024
    risk 0.35cvss 5.4epss 0.00

    CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.