9.8
/ 10
CRITICAL
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Description
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.
AI Analysis
Missing authentication vulnerability allowing unauthenticated attackers to delete member records
Basic Information
ID
CVE-2025-70150
Source
mitre
Published
Feb 18, 2026 at 00:00
Modified
Feb 18, 2026 at 16:51
Affected Product
Vendor
CodeAstro
Product
CodeAstro Membership Management System
Version
1.0
Affected Versions
n/a n/a n/a
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
CodeAstro
Product
Membership Management System
Version
1.0