Impact
The vulnerability allows an attacker to inject arbitrary SQL commands through the fromDate parameter in report.php and revenue_report.php, potentially exposing sensitive data, modifying database contents, or disrupting service. This weakness corresponds to the Input Validation flaw described by CWE‑89.
Affected Systems
CodeAstro Membership Management System 1.0 is affected. No other vendors or product versions are currently known.
Risk and Exploitability
Exploit is likely remote via crafted HTTP requests to the vulnerable pages, as inferred from the description. The CVE has a CVSS score of 9.8 and an EPSS score of less than 1%, indicating a very low but nonzero exploitation probability. It is not listed in the CISA KEV catalog. The potential impact of full database compromise is high.
OpenCVE Enrichment