CVE-2025-11589: CodeAstro Gym Management System user-payment.php sql injection
A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of the argument plan results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11589?
CVE-2025-11589 is a critical vulnerability due to its potential for SQL injection in the CodeAstro Gym Management System.
How do I fix CVE-2025-11589?
To fix CVE-2025-11589, it is recommended to sanitize and validate user inputs appropriately within the affected function to prevent SQL injection.
What is the impact of exploiting CVE-2025-11589?
Exploiting CVE-2025-11589 can allow attackers to manipulate database queries, potentially leading to unauthorized data exposure or alteration.
Which systems are affected by CVE-2025-11589?
CVE-2025-11589 affects the CodeAstro Gym Management System version 1.0 specifically in the /admin/user-payment.php file.
Can CVE-2025-11589 be exploited remotely?
Yes, CVE-2025-11589 can be exploited remotely, making it crucial for users to address the vulnerability promptly.