Skip to content
Noroxi

CodeAstro records

109 published records for vendor codeastro.

All records

109 records
  • An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitra

    HighCVSS 8.8No exploitEPSS 19%

    codeastro · membership management systemFeb 28, 2024

  • SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate p

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · complaint management systemDec 20, 2024

  • CVE-2024-0194
    39Monitor

    CodeAstro Internet Banking System Profile Picture pages_account.php unrestricted upload

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · internet banking systemJan 2, 2024

  • CVE-2024-2351
    39Monitor

    CodeAstro Ecommerce Site Search action.php sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · ecommerce websiteMar 9, 2024

  • CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · membership management systemFeb 18, 2026

  • An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · complaint management systemJan 3, 2025

  • CVE-2024-1824
    39Monitor

    CodeAstro House Rental Management System signing.php sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · house rental management systemFeb 23, 2024

  • Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

    CriticalCVSS 9.8No exploitEPSS 1%

    codeastro · bus ticket booking systemApr 25, 2025

  • CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 0%

    codeastro · membership management systemFeb 18, 2026

  • A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL comma

    CriticalCVSS 9.1No exploitEPSS 1%

    codeastro · membership management systemFeb 28, 2024

  • A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the

    HighCVSS 8.8Proof of conceptEPSS 1%

    codeastro · internet banking systemApr 10, 2025

  • A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL comma

    HighCVSS 8.8No exploitEPSS 1%

    codeastro · membership management systemFeb 28, 2024

  • CVE-2023-6773
    35Monitor

    CodeAstro POS and Inventory Management System User Creation register_account access control

    HighCVSS 8.8No exploitEPSS 1%

    codeastro · pos and inventory management systemDec 13, 2023

  • An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code

    HighCVSS 8.8No exploitEPSS 1%

    codeastro · complaint management systemDec 18, 2024

  • An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

    HighCVSS 8.8No exploitEPSS 1%

    codeastro · complaint management systemDec 18, 2024

  • CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.

    HighCVSS 8.6No exploitEPSS 0%

    codeastro · membership management systemSep 27, 2024

  • Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles.

    HighCVSS 8.0No exploitEPSS 0%

    codeastro · bus ticket booking systemApr 24, 2025

  • CVE-2024-2076
    30Monitor

    CodeAstro House Rental Management System tenant.php missing authentication

    HighCVSS 7.5No exploitEPSS 1%

    codeastro · house rental management systemMar 1, 2024

  • Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to

    HighCVSS 7.5Proof of conceptEPSS 1%

    codeastro · complaint management systemFeb 6, 2025

  • The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, p

    HighCVSS 7.5No exploitEPSS 1%

    codeastro · membership management systemSep 27, 2024

  • CVE-2024-0543
    30Monitor

    CodeAstro Real Estate Management System propertydetail.php sql injection

    HighCVSS 7.5No exploitEPSS 0%

    codeastro · real estate management systemJan 15, 2024

  • Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated a

    HighCVSS 7.5No exploitEPSS 0%

    codeastro · membership management systemFeb 18, 2026

  • A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary J

    HighCVSS 7.3Proof of conceptEPSS 0%

    codeastro · internet banking systemJan 22, 2025

  • An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a cra

    HighCVSS 7.2No exploitEPSS 1%

    codeastro · restaurant pos systemNov 1, 2022

  • CVE-2024-2333
    28Monitor

    CodeAstro Membership Management System add_members.php sql injection

    HighCVSS 7.2No exploitEPSS 1%

    codeastro · membership management systemMar 9, 2024