CVE-2025-4484
Last modified
CVE-2025-4484 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_user. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Admerc | Gym Management System | 1.0 |
References
- https://github.com/wyl091256/CVE/issues/4Exploit, Issue Tracking, Third Party Advisory
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.308199Permissions Required, VDB Entry
- https://vuldb.com/?id.308199Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.566779Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-4484?
How severe is CVE-2025-4484?
How do I fix CVE-2025-4484?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-44831EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnera…9.8
- CVE-2025-44835D-Link DIR-816 A2V1.1.0B05 was found to contain a command in…6.3
- CVE-2025-44836TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to co…6.3
- CVE-2025-44837TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to co…6.3
- CVE-2025-44838TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to co…6.3
- CVE-2025-44839TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
- CVE-2025-44840TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
- CVE-2025-44841TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
- CVE-2025-44842TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
- CVE-2025-44843TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
- CVE-2025-44844TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
- CVE-2025-44845TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain…6.5
Are you affected by CVE-2025-4484?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
