CVE-2025-0231: Codezips Gym Management System submit_payments.php sql injection
A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/submitpayments.php. The manipulation of the argument mid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0231?
CVE-2025-0231 is classified as a critical vulnerability affecting Codezips Gym Management System 1.0.
How does the CVE-2025-0231 vulnerability occur?
CVE-2025-0231 occurs due to SQL injection via the manipulation of the 'm_id' argument in the file /dashboard/admin/submit_payments.php.
What software is affected by CVE-2025-0231?
CVE-2025-0231 specifically affects Codezips Gym Management System version 1.0.
How do I fix CVE-2025-0231?
To fix CVE-2025-0231, it is recommended to sanitize and validate input parameters to prevent SQL injection attacks.
Can CVE-2025-0231 lead to data compromise?
Yes, CVE-2025-0231 can potentially lead to data compromise due to the SQL injection vulnerability.