PT-2025-43922 · Codeastro · Codeastro Gym Management System

·

CVE-2025-12261

·

Published

2025-10-27

·

Updated

2025-10-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeAstro Gym Management System version 1.0
Description A flaw exists in CodeAstro Gym Management System version 1.0 that allows for SQL injection. This occurs through manipulation of the ID argument in the file '/admin/actions/remove-announcement.php'. The attack can be initiated remotely. The exploit has been made public.
Recommendations Apply any available updates or patches to address the SQL injection issue in the '/admin/actions/remove-announcement.php' file. As a temporary workaround, restrict access to the '/admin/actions/remove-announcement.php' file. Sanitize the ID parameter before using it in SQL queries.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12261

Affected Products

Codeastro Gym Management System