CVE-2022-46062
https://notcve.org/view.php?id=CVE-2022-46062
Gym Management System v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). Gym Management System v0.0.1 es vulnerable a la Cross-Site Request Forgery (CSRF). • https://github.com/rdyx0/CVE/blob/master/Gym%20Management%20System/CSRF/delete_user/delete_user.md • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-2842 – SourceCodester Gym Management System login.php sql injection
https://notcve.org/view.php?id=CVE-2022-2842
A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/WhiteA1so/CVE/blob/main/Gym%20Management%20System-loginpage-Sqlinjection.pdf https://vuldb.com/?id.206451 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2022-2800 – SourceCodester Gym Management System clickjacking
https://notcve.org/view.php?id=CVE-2022-2800
A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality. The manipulation leads to clickjacking. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Blythe-LU/Record4/blob/main/Gym%20management%20system%20project%20-%20ClickJacking%20exists%20on%20multiple%20pages.md https://vuldb.com/?id.206246 • CWE-451: User Interface (UI) Misrepresentation of Critical Information CWE-1021: Improper Restriction of Rendered UI Layers or Frames •
CVE-2022-2776 – SourceCodester Gym Management System delete_user.php denial of service
https://notcve.org/view.php?id=CVE-2022-2776
A vulnerability classified as problematic has been found in SourceCodester Gym Management System. Affected is an unknown function of the file delete_user.php. The manipulation of the argument delete_user leads to denial of service. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-206172. • https://vuldb.com/?id.206172 • CWE-404: Improper Resource Shutdown or Release •
CVE-2022-2749 – SourceCodester Gym Management System unrestricted upload
https://notcve.org/view.php?id=CVE-2022-2749
A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?view_exercises. The manipulation leads to unrestricted upload. • https://github.com/Blythe-LU/Record3/blob/main/Gym%20Management%20System%20Project-%20Arbitrary%20file%20upload%20vulnerability.md https://vuldb.com/?id.206017 • CWE-434: Unrestricted Upload of File with Dangerous Type •