Codezips Gym Management System
cpe:2.3:a:codezips:gym_management_system:*:*:*:*:*:*:*
- 1.0
A critical SQL injection vulnerability has been identified in Codezips Gym Management System version 1.0. The issue resides in the rname parameter of the file saveroutine.php within the dashboard/admin directory. This vulnerability allows attackers to inject arbitrary SQL commands, potentially leading to unauthorized database access, data manipulation, and full system compromise.
Exploitation of this vulnerability could result in unauthorized database access, allowing attackers to read, modify, or delete data. There is also a risk of exposing sensitive customer or payment information, disrupting application performance, or escalating privileges for broader system access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.