CVE-2025-4485: itsourcecode Gym Management System ajax.php sql injection
Published May 9, 2025
·Updated
A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=deletetrainer. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
itsourcecode Gym Management System
Admerc Gym Management System=1.0
Event History
May 9, 2025
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4485?
CVE-2025-4485 is classified as a critical vulnerability.
2
How do I fix CVE-2025-4485?
Fixing CVE-2025-4485 involves updating the Gym Management System to the latest version that addresses this SQL injection issue.
3
What type of attack is associated with CVE-2025-4485?
CVE-2025-4485 is associated with SQL injection attacks.
4
Which file is vulnerable in CVE-2025-4485?
The vulnerability in CVE-2025-4485 affects the file /ajax.php?action=delete_trainer.
5
Can CVE-2025-4485 be exploited remotely?
Yes, CVE-2025-4485 can be exploited remotely.