First published: Wed Feb 12 2025(Updated: )
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file /dashboard/admin/viewdetailroutine.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gym Management System | ||
Gym Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1206 has been classified as a critical severity vulnerability.
CVE-2025-1206 allows for SQL injection through manipulation of the 'id' argument in the /dashboard/admin/viewdetailroutine.php file.
Mitigation for CVE-2025-1206 should include input sanitization and implementing prepared statements in database queries.
Exploiting CVE-2025-1206 could lead to unauthorized access to sensitive data and potential database compromise.
As of now, it is recommended to check with the vendor for any available patches or updates addressing CVE-2025-1206.