CNNVD-202511-103 Information

CNNVD ID

CNNVD-202511-103

CVE-2025-12609

  • CNNVD Published: 2025-11-03

Description (Chinese)

CodeAstro Gym Management System是CodeAstro公司的一个健身房管理系统。 CodeAstro Gym Management System 1.0版本存在SQL注入漏洞,该漏洞源于对文件/admin/update-progress.php中参数id/ini_weight的错误操作,可能导致SQL注入攻击。

Description (English)

CodeAstro Gym Management System is a gymnasium management system for CodeAstro. The CodeAstro Gym Management System Version 1.0 has an injection loophole in SQL, which stems from an error in the id/ini water parameter in the document/admin/update-process.php, which may lead to an SQL injection attack.

Hazard Level

High

Vulnerability Type

SQL注入

Affected Vendor

CodeAstro

Published

2025-11-03

Last Modified

2026-02-24

References

https://vuldb.com/?submit.678403 https://codeastro.com/ https://vuldb.com/?ctiid.330904 https://vuldb.com/?submit.678402 https://vuldb.com/?id.330904 https://github.com/iamzzzzz/iam/issues/1

Share on: