Cross-Site Request Forgery Vulnerability in SourceCodester Gym Management System
CVE-2025-6476
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 22 June 2025
Badges
What is CVE-2025-6476?
A vulnerability exists within the SourceCodester Gym Management System 1.0, allowing for the exploitation of an unknown function through cross-site request forgery (CSRF). This security issue can be triggered remotely, enabling attackers to perform unwanted actions on behalf of authenticated users without their consent. As the exploit is publicly disclosed, both system administrators and users must be vigilant and take necessary precautions to secure their systems against potential remote attacks.
Affected Version(s)
Gym Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved