CVE-2026-5206: code-projects Simple Gym Management System Payment sql injection
A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Paymentid/Amount/customerid/paymenttype/customername leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5206?
CVE-2026-5206 is classified as a medium severity vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2026-5206?
To fix CVE-2026-5206, ensure to sanitize and validate all user inputs in the Payment Handler component.
What kind of attack can CVE-2026-5206 lead to?
CVE-2026-5206 can lead to SQL injection attacks, allowing attackers to manipulate database queries.
Which software version is impacted by CVE-2026-5206?
CVE-2026-5206 specifically affects version 1.0 of the Code-Projects Simple Gym Management System.
What components are affected by CVE-2026-5206?
CVE-2026-5206 impacts the Payment Handler component in the Simple Gym Management System.