← Back to browse · API

CVE-2024-25869

Severity
HIGH
CVSS
8.8
EPSS
0.1869
Risk score
41.74
CISA KEV
No
PoC
No
Published
2024-02-28
Modified
2024-08-01
First seen
2026-08-08
Aliases
EUVD-2024-23175, GHSA-3436-JVHW-JV5C
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-23175

Description

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.

References