A vulnerability identified as critical has been detected in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection.
This vulnerability is known as CVE-2025-9766. Remote exploitation of the attack is possible. Furthermore, an exploit is available.