CVE-2025-11591: CodeAstro Gym Management System delete-member.php sql injection
A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11591?
CVE-2025-11591 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-11591?
To fix CVE-2025-11591, sanitize and validate user inputs in the admin actions for the delete-member.php file.
Who is affected by CVE-2025-11591?
CVE-2025-11591 affects users of CodeAstro Gym Management System 1.0 using the vulnerable delete-member.php file.
What type of vulnerability is CVE-2025-11591?
CVE-2025-11591 is a SQL injection vulnerability that can be exploited by manipulating the ID parameter.
Can CVE-2025-11591 be exploited remotely?
Yes, CVE-2025-11591 can be exploited remotely, allowing attackers to compromise the system from a distance.