CVE-2025-11588: CodeAstro Gym Management System index.php sql injection
A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11588?
CVE-2025-11588 is categorized as a medium severity SQL injection vulnerability that allows remote attackers to manipulate database queries.
How do I fix CVE-2025-11588?
To fix CVE-2025-11588, sanitize and validate user inputs in the fullname parameter to prevent SQL injection.
What software versions are affected by CVE-2025-11588?
CVE-2025-11588 affects the CodeAstro Gym Management System version 1.0.
Can CVE-2025-11588 be exploited remotely?
Yes, CVE-2025-11588 can be exploited remotely by manipulating the fullname argument.
What impact does CVE-2025-11588 have?
The impact of CVE-2025-11588 includes potential unauthorized access to the database, data leakage, and data manipulation.