CVE-2026-7553 Details
Description
A vulnerability was found in code-projects Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_exercises.php. The manipulation of the argument edit_exercise results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
A SQL injection vulnerability has been identified in Code-Projects Gym Management System version 1.0. The issue arises in the file '/admin/edit_exercises.php', where user-controlled input in the 'edit_exercise' parameter is not properly sanitized or parameterized before being used in SQL queries. This oversight allows for the manipulation of SQL logic, potentially leading to unauthorized data access, data tampering, or a full database compromise, depending on database permissions and the depth of exploitation.
It is recommended to use prepared statements with bound parameters for all SQL queries to prevent SQL injection vulnerabilities. Additionally, input validation should be implemented to ensure that only expected data types are accepted. Applying least-privilege principles to database accounts and centralizing error handling to avoid disclosing SQL-related information can further enhance security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2026CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-projects.org/ | [email protected] | ProductVendor |
| https://fox-byte.yuque.com/org-wiki-fox-byte-ig3xms/rdgsp5/yg012bnp1xorwq0p | [email protected] | ExploitRemedy |
| https://vuldb.com/submit/805603 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360361 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360361/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Code-Projects Gym Management System | 1.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | New CVE Received | [email protected] |
Volerion