CVE-2025-11590: CodeAstro Gym Management System equipment-entry.php sql injection
A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11590?
CVE-2025-11590 has a high severity rating due to the potential for remote SQL injection.
How do I fix CVE-2025-11590?
To fix CVE-2025-11590, sanitize user inputs in the equipment-entry.php file, particularly the 'ename' argument.
What software is affected by CVE-2025-11590?
CVE-2025-11590 affects CodeAstro Gym Management System version 1.0.
Can CVE-2025-11590 be exploited remotely?
Yes, CVE-2025-11590 allows for remote exploitation through SQL injection.
What are the potential impacts of CVE-2025-11590?
The potential impacts of CVE-2025-11590 include unauthorized access to sensitive data and potential database compromise.