CVE-2026-4550

MEDIUM

code-projects Simple Gym Management System func.php sql injection

Title source: cna

Description

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 4.7
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
code-projects/Simple Gym Management System < 1.0
Published Mar 22, 2026
Tracked Since Mar 22, 2026