CVE-2025-4363: itsourcecode Gym Management System ajax.php sql injection
A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=endmembership. The manipulation of the argument rid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4363?
CVE-2025-4363 is classified as a critical vulnerability.
How does CVE-2025-4363 affect the Gym Management System?
CVE-2025-4363 allows for SQL injection through manipulation of the 'rid' argument in the /ajax.php?action=end_membership file.
What are the potential impacts of exploiting CVE-2025-4363?
Exploitation of CVE-2025-4363 may lead to unauthorized database access and data leakage.
How do I fix CVE-2025-4363?
To fix CVE-2025-4363, sanitize and validate input parameters to prevent SQL injection.
Is there a patch available for CVE-2025-4363 in the Gym Management System?
As of now, no official patch has been released for CVE-2025-4363 for the Gym Management System.