SQL Injection Vulnerability in ProjectWorlds Gym Management System by ProjectWorlds
CVE-2025-60311
8.8HIGH
What is CVE-2025-60311?
The ProjectWorlds Gym Management System version 1.0 contains a SQL Injection vulnerability through the 'id' parameter within the profile/edit.php page. This allows an attacker to execute arbitrary SQL queries, potentially compromising user data and the overall integrity of the system. Proper input validation and sanitation are critical to mitigate this risk.
