CVE-2025-13172: CodeAstro Gym Management System view-member-report.php sql injection
A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13172?
CVE-2025-13172 is considered a high-severity vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-13172?
To fix CVE-2025-13172, ensure proper input validation and use prepared statements in the codebase.
What components are affected by CVE-2025-13172?
CVE-2025-13172 affects the CodeAstro Gym Management System version 1.0, specifically the /admin/view-member-report.php file.
Can CVE-2025-13172 be exploited remotely?
Yes, CVE-2025-13172 can be exploited remotely by manipulating the argument ID.
What type of vulnerability is CVE-2025-13172?
CVE-2025-13172 is classified as an SQL injection vulnerability.