A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/actions/remove-announcement.php. Performing manipulation of the argument ID results in sql injection.
The attack can be initiated remotely. The exploit has been made public and could be used.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Codeastro Gym_Management_System
cpe:2.3:a:codeastro:gym_management_system:1.0:*:*:*:*:*:*:*
|
— | — |