CVE-2025-1183: CodeZips Gym Management System more-userprofile.php sql injection
A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/admin/more-userprofile.php. The manipulation of the argument loginid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1183?
CVE-2025-1183 is classified as a critical vulnerability.
How does CVE-2025-1183 exploit SQL injection?
CVE-2025-1183 exploits SQL injection through the manipulation of the login_id argument in the file /dashboard/admin/more-userprofile.php.
Which software version is affected by CVE-2025-1183?
CVE-2025-1183 affects CodeZips Gym Management System version 1.0.
What is the potential impact of CVE-2025-1183?
The potential impact of CVE-2025-1183 includes unauthorized access to sensitive data and database manipulation.
How can I mitigate CVE-2025-1183?
Mitigation for CVE-2025-1183 includes validating and sanitizing user inputs for SQL queries and applying security patches from the vendor.