Impact
A vulnerability exists in the admin/edit_exercises.php script of the Gym Management System. Manipulating the edit_exercise parameter allows an attacker to inject arbitrary SQL commands, potentially compromising the integrity and confidentiality of the underlying database. The flaw corresponds to CWE-74 and CWE-89, indicating unsanitized input leading to injection.
Affected Systems
The affected product is code-projects Gym Management System version 1.0. The vulnerability is located in the /admin/edit_exercises.php functionality of that version.
Risk and Exploitability
The CVSS score is 5.1, indicating medium severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote; an attacker can trigger the injection via the web interface from outside the network. The public availability of the exploit means that a determined adversary could launch an attack without requiring privileged access.
OpenCVE Enrichment