CVE-2025-67146 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.p…
Critical CVSS: 9.4

CVE-2025-67146

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can exploit these issues to inject malicious SQL commands, leading to unauthorized data extraction, authentication bypass, or modification of database contents.
Vendor
Abhishekmali21
Product
Gym Management System
CWE
CWE-89
Yayın Tarihi
2026-01-12 22:16:07
Güncelleme
2026-01-27 20:22:14
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar