CNNVD-202601-1805 Information

CNNVD ID

CNNVD-202601-1805

CVE-2025-67146

  • CNNVD Published: 2026-01-12

Description (Chinese)

GYM-MANAGEMENT-SYSTEM是Abhishek S个人开发者的一个健身房管理系统。 GYM-MANAGEMENT-SYSTEM 1.0版本存在安全漏洞,该漏洞源于member_search.php、trainer_search.php和gym_search.php中的name参数以及payment_search.php中的id参数未经验证,可能导致SQL注入攻击。

Description (English)

GYM-MANAGEMENT-SYSTEM is a gymnasium management system for Abhishek S personal developers. There is a security loophole in version 1.0 of GYM-MANAGEMENT-SYSTEM, which originates from the name parameters in members search.php, Trainer search.php and gym search.php, as well as the id parameters in Payment search.php, which could lead to SQL injection attacks.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2026-01-12

Last Modified

2026-02-24

References

https://github.com/AbhishekMali21/GYM-MANAGEMENT-SYSTEM/issues/4 https://access.redhat.com/security/cve/cve-2025-67146

Share on: