First published: Fri May 09 2025(Updated: )
A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=delete_trainer. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
itsourcecode Gym Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4485 is classified as a critical vulnerability.
Fixing CVE-2025-4485 involves updating the Gym Management System to the latest version that addresses this SQL injection issue.
CVE-2025-4485 is associated with SQL injection attacks.
The vulnerability in CVE-2025-4485 affects the file /ajax.php?action=delete_trainer.
Yes, CVE-2025-4485 can be exploited remotely.