Cross-Site Request Forgery Vulnerability in phpgurukul Gym Management System
CVE-2024-55271
3.5LOW
What is CVE-2024-55271?
A vulnerability in the phpgurukul Gym Management System allows an attacker to exploit the profile update functionality within the User Panel. By crafting a malicious request, an attacker can execute unauthorized actions on behalf of a user without their consent. This vulnerability resides specifically in the /profile.php endpoint, which can lead to undesirable modifications and breaches of user privacy.
