CVE-2025-4488: itsourcecode Gym Management System ajax.php sql injection
A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=deletepackage. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4488?
CVE-2025-4488 has been declared as critical due to the potential for SQL injection vulnerabilities.
How do I fix CVE-2025-4488?
To fix CVE-2025-4488, ensure that input handling in the /ajax.php?action=delete_package file is properly sanitized and validated.
What type of vulnerability is CVE-2025-4488?
CVE-2025-4488 is an SQL injection vulnerability affecting the Gym Management System.
What is affected by CVE-2025-4488?
CVE-2025-4488 affects the Gym Management System version 1.0 specifically in the ajax.php file.
Can CVE-2025-4488 be exploited remotely?
Yes, CVE-2025-4488 can potentially be exploited remotely by manipulating the ID argument in the affected functionality.