codeastro kayıtları
codeastro üreticisine ait 109 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')44
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')13
- CWE-284 Improper Access Control7
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-352 Cross-Site Request Forgery (CSRF)4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
109 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2024-25869İstismar yok | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitracodeastro · membership management system · CWE-434 | Yüksek8,8 | — | %18,7 | 28 Şub 2024 |
39İzleyin | CVE-2024-55509İstismar yok | SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate pcodeastro · complaint management system · CWE-89 | Kritik9,8 | — | %0,8 | 20 Ara 2024 |
39İzleyin | CVE-2024-0194İstismar yok | CodeAstro Internet Banking System Profile Picture pages_account.php unrestricted uploadcodeastro · internet banking system · CWE-434 | Kritik9,8 | — | %0,7 | 2 Oca 2024 |
39İzleyin | CVE-2024-2351İstismar yok | CodeAstro Ecommerce Site Search action.php sql injectioncodeastro · ecommerce website · CWE-89 | Kritik9,8 | — | %0,7 | 9 Mar 2024 |
39İzleyin | CVE-2025-70150İstismar yok | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticatedcodeastro · membership management system · CWE-862 | Kritik9,8 | — | %0,7 | 18 Şub 2026 |
39İzleyin | CVE-2024-55507İstismar yok | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.codeastro · complaint management system · CWE-281 | Kritik9,8 | — | %0,6 | 3 Oca 2025 |
39İzleyin | CVE-2024-1824İstismar yok | CodeAstro House Rental Management System signing.php sql injectioncodeastro · house rental management system · CWE-89 | Kritik9,8 | — | %0,6 | 23 Şub 2024 |
39İzleyin | CVE-2025-25775İstismar yok | Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.codeastro · bus ticket booking system · CWE-89 | Kritik9,8 | — | %0,5 | 25 Nis 2025 |
39İzleyin | CVE-2025-70149Kavram kanıtı | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.codeastro · membership management system · CWE-89 | Kritik9,8 | — | %0,4 | 18 Şub 2026 |
36İzleyin | CVE-2024-25867İstismar yok | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commacodeastro · membership management system · CWE-89 | Kritik9,1 | — | %0,7 | 28 Şub 2024 |
35İzleyin | CVE-2025-29017Kavram kanıtı | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in thecodeastro · internet banking system · CWE-434 | Yüksek8,8 | — | %0,9 | 10 Nis 2025 |
35İzleyin | CVE-2024-25866İstismar yok | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commacodeastro · membership management system · CWE-89 | Yüksek8,8 | — | %0,8 | 28 Şub 2024 |
35İzleyin | CVE-2023-6773İstismar yok | CodeAstro POS and Inventory Management System User Creation register_account access controlcodeastro · pos and inventory management system · CWE-284 | Yüksek8,8 | — | %0,7 | 13 Ara 2023 |
35İzleyin | CVE-2024-55506İstismar yok | An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary codecodeastro · complaint management system · CWE-639 | Yüksek8,8 | — | %0,7 | 18 Ara 2024 |
35İzleyin | CVE-2024-55505İstismar yok | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.codeastro · complaint management system · CWE-94 | Yüksek8,8 | — | %0,7 | 18 Ara 2024 |
34İzleyin | CVE-2024-46472İstismar yok | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.codeastro · membership management system · CWE-89 | Yüksek8,6 | — | %0,4 | 27 Eyl 2024 |
32İzleyin | CVE-2025-25777İstismar yok | Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles.codeastro · bus ticket booking system · CWE-639 | Yüksek8,0 | — | %0,3 | 24 Nis 2025 |
30İzleyin | CVE-2024-2076İstismar yok | CodeAstro House Rental Management System tenant.php missing authenticationcodeastro · house rental management system · CWE-306 | Yüksek7,5 | — | %0,9 | 1 Mar 2024 |
30İzleyin | CVE-2024-56889Kavram kanıtı | Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to codeastro · complaint management system · CWE-284 | Yüksek7,5 | — | %0,7 | 6 Şub 2025 |
30İzleyin | CVE-2024-46471İstismar yok | The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, pcodeastro · membership management system · CWE-200 | Yüksek7,5 | — | %0,5 | 27 Eyl 2024 |
30İzleyin | CVE-2024-0543İstismar yok | CodeAstro Real Estate Management System propertydetail.php sql injectioncodeastro · real estate management system · CWE-89 | Yüksek7,5 | — | %0,5 | 15 Oca 2024 |
30İzleyin | CVE-2025-70148İstismar yok | Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated acodeastro · membership management system · CWE-862 | Yüksek7,5 | — | %0,4 | 18 Şub 2026 |
29İzleyin | CVE-2024-56924Kavram kanıtı | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary Jcodeastro · internet banking system · CWE-352 | Yüksek7,3 | — | %0,5 | 22 Oca 2025 |
28İzleyin | CVE-2022-43085İstismar yok | An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a cracodeastro · restaurant pos system · CWE-434 | Yüksek7,2 | — | %1,1 | 1 Kas 2022 |
28İzleyin | CVE-2024-2333İstismar yok | CodeAstro Membership Management System add_members.php sql injectioncodeastro · membership management system · CWE-89 | Yüksek7,2 | — | %0,7 | 9 Mar 2024 |
- CVE-2024-2586941Planlayın
An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitra
YüksekCVSS 8,8İstismar yokEPSS %19codeastro · membership management system28 Şub 2024
- CVE-2024-5550939İzleyin
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate p
KritikCVSS 9,8İstismar yokEPSS %1codeastro · complaint management system20 Ara 2024
- CVE-2024-019439İzleyin
CodeAstro Internet Banking System Profile Picture pages_account.php unrestricted upload
KritikCVSS 9,8İstismar yokEPSS %1codeastro · internet banking system2 Oca 2024
- CVE-2024-235139İzleyin
CodeAstro Ecommerce Site Search action.php sql injection
KritikCVSS 9,8İstismar yokEPSS %1codeastro · ecommerce website9 Mar 2024
- CVE-2025-7015039İzleyin
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated
KritikCVSS 9,8İstismar yokEPSS %1codeastro · membership management system18 Şub 2026
- CVE-2024-5550739İzleyin
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
KritikCVSS 9,8İstismar yokEPSS %1codeastro · complaint management system3 Oca 2025
- CVE-2024-182439İzleyin
CodeAstro House Rental Management System signing.php sql injection
KritikCVSS 9,8İstismar yokEPSS %1codeastro · house rental management system23 Şub 2024
- CVE-2025-2577539İzleyin
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
KritikCVSS 9,8İstismar yokEPSS %1codeastro · bus ticket booking system25 Nis 2025
- CVE-2025-7014939İzleyin
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %0codeastro · membership management system18 Şub 2026
- CVE-2024-2586736İzleyin
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL comma
KritikCVSS 9,1İstismar yokEPSS %1codeastro · membership management system28 Şub 2024
- CVE-2025-2901735İzleyin
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the
YüksekCVSS 8,8Kavram kanıtıEPSS %1codeastro · internet banking system10 Nis 2025
- CVE-2024-2586635İzleyin
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL comma
YüksekCVSS 8,8İstismar yokEPSS %1codeastro · membership management system28 Şub 2024
- CVE-2023-677335İzleyin
CodeAstro POS and Inventory Management System User Creation register_account access control
YüksekCVSS 8,8İstismar yokEPSS %1codeastro · pos and inventory management system13 Ara 2023
- CVE-2024-5550635İzleyin
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code
YüksekCVSS 8,8İstismar yokEPSS %1codeastro · complaint management system18 Ara 2024
- CVE-2024-5550535İzleyin
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.
YüksekCVSS 8,8İstismar yokEPSS %1codeastro · complaint management system18 Ara 2024
- CVE-2024-4647234İzleyin
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
YüksekCVSS 8,6İstismar yokEPSS %0codeastro · membership management system27 Eyl 2024
- CVE-2025-2577732İzleyin
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles.
YüksekCVSS 8,0İstismar yokEPSS %0codeastro · bus ticket booking system24 Nis 2025
- CVE-2024-207630İzleyin
CodeAstro House Rental Management System tenant.php missing authentication
YüksekCVSS 7,5İstismar yokEPSS %1codeastro · house rental management system1 Mar 2024
- CVE-2024-5688930İzleyin
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %1codeastro · complaint management system6 Şub 2025
- CVE-2024-4647130İzleyin
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, p
YüksekCVSS 7,5İstismar yokEPSS %1codeastro · membership management system27 Eyl 2024
- CVE-2024-054330İzleyin
CodeAstro Real Estate Management System propertydetail.php sql injection
YüksekCVSS 7,5İstismar yokEPSS %0codeastro · real estate management system15 Oca 2024
- CVE-2025-7014830İzleyin
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated a
YüksekCVSS 7,5İstismar yokEPSS %0codeastro · membership management system18 Şub 2026
- CVE-2024-5692429İzleyin
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary J
YüksekCVSS 7,3Kavram kanıtıEPSS %0codeastro · internet banking system22 Oca 2025
- CVE-2022-4308528İzleyin
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a cra
YüksekCVSS 7,2İstismar yokEPSS %1codeastro · restaurant pos system1 Kas 2022
- CVE-2024-233328İzleyin
CodeAstro Membership Management System add_members.php sql injection
YüksekCVSS 7,2İstismar yokEPSS %1codeastro · membership management system9 Mar 2024