CVE-2025-4360: itsourcecode Gym Management System view_member.php sql injection
A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /viewmember.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4360?
CVE-2025-4360 is classified as a critical vulnerability.
What is the nature of the vulnerability in CVE-2025-4360?
CVE-2025-4360 involves a SQL injection vulnerability in the /view_member.php file.
How can CVE-2025-4360 be exploited?
CVE-2025-4360 can be exploited by manipulating the 'ID' argument to perform SQL injection attacks.
How do I fix CVE-2025-4360?
To fix CVE-2025-4360, validate and sanitize user inputs for the ID parameter in the affected file.
Is CVE-2025-4360 present in all versions of the Gym Management System?
CVE-2025-4360 affects Gym Management System version 1.0 and may potentially impact other versions.