SQL Injection Vulnerability in Code-Projects Gym Management System by Code-Projects
CVE-2026-7716
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 4 May 2026
Badges
What is CVE-2026-7716?
A SQL injection vulnerability has been identified in the Code-Projects Gym Management System, specifically affecting the file /index.php. This flaw occurs due to improper handling of input parameters in the 'day' argument, allowing attackers to execute arbitrary SQL commands remotely. The public disclosure of this exploit raises concerns for users of this PHP application on Windows NT, making it crucial for organizations to assess their security posture and implement necessary patches or mitigations.
Affected Version(s)
Gym Management System In PHP 1.0
Windows NT 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
