Vulnerability Description
Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and 'login_key' parameters in (3) change_s_pwd.php. An unauthenticated or authenticated attacker can exploit these issues to bypass authentication, execute arbitrary SQL commands, modify database records, delete data, or escalate privileges to administrator level.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-67147?
CVE-2025-67147 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key'...
How severe is CVE-2025-67147?
CVE-2025-67147 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-67147?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.