First published: Wed Feb 12 2025(Updated: )
A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/more-userprofile.php. The manipulation of the argument login_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gym Management System | ||
Gym Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1183 is classified as a critical vulnerability.
CVE-2025-1183 exploits SQL injection through the manipulation of the login_id argument in the file /dashboard/admin/more-userprofile.php.
CVE-2025-1183 affects CodeZips Gym Management System version 1.0.
The potential impact of CVE-2025-1183 includes unauthorized access to sensitive data and database manipulation.
Mitigation for CVE-2025-1183 includes validating and sanitizing user inputs for SQL queries and applying security patches from the vendor.