Filtered by vendor Codeastro Subscriptions
Filtered by product Membership Management System Subscriptions
Total 6 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-46236 1 Codeastro 1 Membership Management System 2024-10-23 5.4 Medium
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and edit_member.php.
CVE-2024-48709 1 Codeastro 1 Membership Management System 2024-10-23 5.4 Medium
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
CVE-2024-46471 1 Codeastro 1 Membership Management System 2024-09-30 7.5 High
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.
CVE-2024-46472 1 Codeastro 1 Membership Management System 2024-09-30 8.6 High
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
CVE-2024-46470 1 Codeastro 1 Membership Management System 2024-09-30 6.1 Medium
Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.
CVE-2024-45528 1 Codeastro 1 Membership Management System 2024-09-03 5.4 Medium
CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.