First published: Thu Sep 28 2017(Updated: )
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dasinfomedia Wpgym Gym Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14844 is classified as a medium-severity vulnerability due to its potential for exploitation via SQL injection.
To fix CVE-2017-14844, you should update the WPGYM WordPress Gym Management System to the latest version provided by Dasinfomedia.
CVE-2017-14844 affects the WPGYM Gym Management System plugin for WordPress versions affected by SQL injection vulnerabilities.
In the context of CVE-2017-14844, SQL injection allows an attacker to execute arbitrary SQL queries via the 'id' parameter, potentially compromising the database.
You can determine if you're vulnerable to CVE-2017-14844 by checking if you are using an affected version of the WPGYM plugin that allows SQL injection via the id parameter.