VYPR
Unrated severityNVD Advisory· Published Mar 4, 2025· Updated Apr 2, 2025

Codezips Gym Management System change_s_pwd.php sql injection

CVE-2025-1959

Description

A vulnerability, which was classified as critical, was found in Codezips Gym Management System 1.0. Affected is an unknown function of the file /change_s_pwd.php. The manipulation of the argument login_id/login_key leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.