CVE-2025-4464: itsourcecode Gym Management System ajax.php sql injection
A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=saveplan. The manipulation of the argument plan leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4464?
CVE-2025-4464 is classified as a critical vulnerability that poses a significant risk to affected systems.
How do I fix CVE-2025-4464?
To fix CVE-2025-4464, it is recommended to update the itsourcecode Gym Management System to the latest version to mitigate SQL injection risks.
What type of vulnerability is CVE-2025-4464?
CVE-2025-4464 is an SQL injection vulnerability that allows attackers to manipulate database queries through unsanitized input.
Which file is affected by CVE-2025-4464?
CVE-2025-4464 specifically affects the /ajax.php?action=save_plan functionality in the itsourcecode Gym Management System.
Who is impacted by CVE-2025-4464?
Any user or administrator using the itsourcecode Gym Management System 1.0 is potentially impacted by CVE-2025-4464.