First published: Thu Mar 27 2025(Updated: )
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gym Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2847 is classified as critical due to its potential for SQL injection exploitation.
To fix CVE-2025-2847, ensure proper input validation and parameterized queries in the /dashboard/admin/over_month.php file.
CVE-2025-2847 affects Codezips Gym Management System version 1.0.
The potential impacts of CVE-2025-2847 include unauthorized access to the database and data leakage.
You can determine if your system is vulnerable to CVE-2025-2847 by testing the /dashboard/admin/over_month.php file for SQL injection vulnerabilities.