A vulnerability, which was classified as critical, was found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing manipulation of the argument ename can lead to sql injection.

This vulnerability is registered as CVE-2025-11590. It is possible to launch the attack remotely. Furthermore, an exploit is available.