CodeAstro Membership Management System 10 SQL Injection (CVE-2024-2333) – Medium -DC-Oct2026-2785

Listen to this Post

The vulnerability CVE-2024-2333 affects CodeAstro Membership Management System 1.0. It is a SQL injection flaw located in the `/add_members.php` file, where the `fullname` parameter is not properly sanitized before being included in an SQL query. An attacker can inject malicious SQL code through the `fullname` argument, potentially allowing them to read, modify, or delete sensitive data from the underlying database. The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The attack can be launched remotely, and a public exploit has been disclosed. The CVSS base score is 6.3 (Medium), with an exploitability score of 2.8 and an impact score of 3.4. The vulnerability was published on 2024-03-09 and last modified on 2024-03-11. The affected component is the `add_members.php` file, which is part of the membership management functionality. The SQL injection occurs because user-supplied input is directly concatenated into an SQL statement without proper validation or escaping. This allows an attacker to alter the query’s logic, potentially bypassing authentication or extracting unauthorized information. The vulnerability is remotely exploitable and requires no authentication, making it a significant risk for exposed instances. The exploit has been publicly disclosed and may be used by attackers. The identifier for this vulnerability is VDB-256284, assigned by VulDB.

DailyCVE Form:

Platform: CodeAstro
Version: 1.0
Vulnerability: SQL Injection
Severity: Medium
date: 2024-03-09

Prediction: 2024-04-15

What Undercode Say:

curl -X POST http://target/add_members.php \
-d "fullname=' OR '1'='1' -- -&[email protected]&password=test"
SELECT FROM members WHERE fullname = '' OR '1'='1' -- -';

Exploit: (Educational Purposes!)

sqlmap -u "http://target/add_members.php" --data="fullname=test&[email protected]&password=test" --dbs
sqlmap -u "http://target/add_members.php" --data="fullname=test&[email protected]&password=test" -D database_name --tables

Protection: from this CVE

$fullname = mysqli_real_escape_string($conn, $_POST['fullname']);
$query = "SELECT FROM members WHERE fullname = '$fullname'";
Use prepared statements
$stmt = $conn->prepare("SELECT FROM members WHERE fullname = ?");
$stmt->bind_param("s", $fullname);
$stmt->execute();

Impact:

Successful exploitation of CVE-2024-2333 allows an attacker to execute arbitrary SQL queries against the vulnerable database. This can lead to unauthorized access to sensitive information, including member records, credentials, and personal data. In severe cases, the attacker may be able to modify or delete data, or even escalate privileges within the application. The vulnerability is remotely exploitable and requires no authentication, making it a critical risk for any publicly accessible instance of CodeAstro Membership Management System 1.0.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top