Security Advisory

CVE-2023-5185

9.1
CRITICAL

Vulnerability Description

Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Published Date September 28, 2023
Official Source NIST NVD Advisory