Update: CVE-2025-67146 - AbhishekMali21 GYM-MANAGEMENT-SYSTEM SQL Injection Vulnerabilities

Update: CVE-2025-67146 - AbhishekMali21 GYM-MANAGEMENT-SYSTEM SQL Injection Vulnerabilities

CVE ID : CVE-2025-67146 Published : Jan. 12, 2026, 10:16 p.m. | 32 minutes ago Description : Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issues to inject malicious SQL commands, leading to unauthorized data extraction, authentication bypass, or modification of database contents. Severity: 9.4 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
Jan. 12, 2026
Affected Product: php
Impact: SQL Injection

Source: Telegram CVE Monitor