SQL Injection Vulnerability in itsourcecode Gym Management System 1.0
CVE-2025-4465
Key Information:
- Vendor
Itsourcecode
- Status
- Vendor
- CVE Published:
- 9 May 2025
Badges
What is CVE-2025-4465?
A vulnerability exists in the itsourcecode Gym Management System 1.0, associated with the file /ajax.php?action=save_schedule. This issue stems from improper handling of the member_id parameter, allowing an attacker to perform SQL injection attacks. Such vulnerabilities can be exploited remotely, enabling unauthorized access or manipulation of the database. The exploit details have been publicly disclosed, increasing the risk for systems still using the affected version.
Affected Version(s)
Gym Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved