SQL Injection Vulnerability in Gym Management System by Code-Projects
CVE-2026-7553
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 1 May 2026
Badges
What is CVE-2026-7553?
A critical SQL injection vulnerability exists in the Gym Management System version 1.0, specifically within the file /admin/edit_exercises.php. By manipulating the edit_exercise parameter, an attacker can execute arbitrary SQL queries, potentially compromising the database and extracting sensitive information. This vulnerability can be exploited remotely, making it imperative for users to apply necessary security measures to protect their applications. Publicly known exploits increase the urgency for users to address this issue immediately.
Affected Version(s)
Gym Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
