ultiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (3) change_s_pwd.php. An unauthenticated or authenticated attacker can exploit these issues to bypass authentication, execute arbitrary SQL commands, modify database records, delete data, or escalate privileges to administrator level.
No configuration.
12 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
12 Jan 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-01-12 21:15
Updated : 2026-01-13 14:03
NVD link : CVE-2025-67147
Mitre link : CVE-2025-67147
CVE.ORG link : CVE-2025-67147
JSON object : View
No product.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')