First published: Fri May 09 2025(Updated: )
A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation of the argument plan leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
itsourcecode Gym Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4464 is classified as a critical vulnerability that poses a significant risk to affected systems.
To fix CVE-2025-4464, it is recommended to update the itsourcecode Gym Management System to the latest version to mitigate SQL injection risks.
CVE-2025-4464 is an SQL injection vulnerability that allows attackers to manipulate database queries through unsanitized input.
CVE-2025-4464 specifically affects the /ajax.php?action=save_plan functionality in the itsourcecode Gym Management System.
Any user or administrator using the itsourcecode Gym Management System 1.0 is potentially impacted by CVE-2025-4464.