CVE-2025-4362: itsourcecode Gym Management System ajax.php sql injection
A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=savemembership. The manipulation of the argument memberid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4362?
CVE-2025-4362 is classified as a critical vulnerability due to its potential to allow SQL injection.
How do I fix CVE-2025-4362?
To fix CVE-2025-4362, ensure proper input validation and parameterized queries to prevent SQL injection in /ajax.php?action=save_membership.
Who is affected by CVE-2025-4362?
CVE-2025-4362 affects users of the itsourcecode Gym Management System version 1.0.
Can CVE-2025-4362 be exploited remotely?
Yes, CVE-2025-4362 can be exploited remotely by manipulating the member_id argument.
What type of vulnerability is CVE-2025-4362?
CVE-2025-4362 is an SQL injection vulnerability allowing attackers to manipulate database queries.