CVE-2025-67147 - AmanSuryawanshi Gym Management System PHP SQL Injection Vulnerability

CVE-2025-67147 - AmanSuryawanshi Gym Management System PHP SQL Injection Vulnerability

CVE ID : CVE-2025-67147 Published : Jan. 12, 2026, 9:15 p.m. | 1 hour, 33 minutes ago Description : Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (3) change_s_pwd.php. An unauthenticated or authenticated attacker can exploit these issues to bypass authentication, execute arbitrary SQL commands, modify database records, delete data, or escalate privileges to administrator level. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
Jan. 12, 2026
Affected Product: PHP
Impact: SQL Injection

Source: Telegram CVE Monitor