5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/actions/check-attendance.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-12242
Source
VulDB
Published
Oct 27, 2025 at 07:02
Affected Product
Vendor
CodeAstro
Product
Gym Management System
Version
1.0
Affected Versions
CodeAstro Gym Management System 1.0