CVE-2024-40488: Lopalopa Live Membership System
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
Affected products
- Lopalopa Live Membership System: version 1.0 only
Published 2024-08-12. Last modified 2026-06-17.