CodeAstro Membership Management System 1.0 contains an SQL injection vulnerability in its membership-card printing functionality. User-controlled input from the ID parameter is incorporated into a database query without adequate parameterization, permitting manipulation of the query syntax.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small research/documentation-style exploit project rather than a source-code exploit implementation. It contains three text/markdown files: a README describing the vulnerability and lab results, a file of exploitation commands, and a file of mitigation guidance. There is no standalone exploit program; instead, the repository documents how to manually verify and then automate exploitation of a SQL injection in CodeAstro Membership Management System v1.0, identified as CVE-2025-70149. The main exploit capability is unauthenticated web-based SQL injection against the id parameter of /membership/print_membership_card.php. The documented workflow starts with manual boolean/error-style probing using crafted URLs, then escalates to automated exploitation with sqlmap. The sqlmap commands show the intended objectives clearly: detect the injection point, enumerate databases, enumerate tables in the membershiphp database, dump the members table, and dump the users table to retrieve admin credentials. The README states the observed outcome was full remote database dumping, extraction of 9 member records, retrieval of admin credentials, and cracking of an MD5 hash. Repository structure is minimal: 'Exploitation commands Used.txt' contains the actionable attack steps and is the closest thing to an entry point; 'Mitation Fixes.txt' documents remediation changes for the vulnerable PHP file, including numeric input validation, prepared statements, disabled verbose error reporting, and creation of a least-privilege MySQL user; 'README.md' provides vulnerability metadata, lab topology, results, and ATT&CK mappings. Because the repository contains only documentation and command examples, its maturity is best classified as POC rather than operational tooling. It is still a valid exploit repository because it provides reproducible exploitation steps and concrete target details, but it does not include custom exploit code beyond sqlmap command usage.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An SQL injection vulnerability in CodeAstro Membership Management System 1.0. The flaw is reachable through the ID parameter of print_membership_card.php.
A SQL injection vulnerability in CodeAstro Membership Management System 1.0 affecting the print_membership_card.php endpoint via the ID parameter.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.