CVE-2025-4464 | itsourcecode Gym Management System 1.0 ajax.php?action=save_plan sql injection
A vulnerability described as critical has been identified in itsourcecode Gym Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_plan. The manipulation of the argument plan results in sql injection.
This vulnerability is reported as CVE-2025-4464. The attack can be launched remotely. Moreover, an exploit is present.