Multiple SQL injection vulnerabilities in amansuryawanshi Gym-Management-System-PHP 1.0 affect several PHP endpoints due to improper neutralization of user-controlled input used in SQL queries. The vulnerable parameters are: (1) submit_contact.php: name, email, comment; (2) secure_login.php: username, pass_key; and (3) change_s_pwd.php: login_id, pwfield, login_key. Exploitation allows attackers to inject arbitrary SQL into backend database operations, enabling authentication bypass and direct manipulation of application data and authorization state.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small PHP proof-of-concept collection for two web application SQL injection issues labeled CVE-2025-67146 and CVE-2025-67147. It is not a packaged exploit framework; instead, it contains vulnerable application-side PHP scripts that illustrate the flaws directly. Repository structure: there are 8 files total, including 7 PHP files and a minimal README. The CVE-2025-67146 directory contains four search handlers: gym_search.php, member_search.php, payment_search.php, and trainer_search.php. Each accepts attacker-controlled POST input and concatenates it directly into a SQL LIKE clause without parameterization. These scripts query the gym, member, payment, and trainer tables respectively, then render matching rows and expose linked update/delete actions through home.php query parameters. The CVE-2025-67147 directory contains three PHP scripts: change_s_pwd.php, secure_login.php, and submit_contact.php. change_s_pwd.php is the most clearly vulnerable: it reads login_key, pwfield, login_id, and confirmfield from POST and builds SQL using direct string interpolation in both SELECT and UPDATE operations against the admin table. This can plausibly enable unauthorized password reset or manipulation if exploited. submit_contact.php is also vulnerable because it inserts unsanitized REQUEST parameters directly into an INSERT statement for the contact table. secure_login.php performs some trimming, stripslashes, and mysqli_real_escape_string before querying the admin table, so it is less obviously injectable than the others, though it remains part of the same insecure application flow. Main exploit capability: exploitation is web-based SQL injection through exposed PHP endpoints. The code does not contain a standalone attacker automation script, reverse shell, or post-exploitation payload. Instead, it demonstrates vulnerable sinks that an attacker could target remotely over HTTP by sending crafted form parameters. Because there is no automated exploitation tooling or customizable payload delivery, the maturity is best classified as POC. Notable fingerprintable artifacts include local application routes such as home.php, index.php, forgot_password.php, contact.php, and ./dashboard/admin/, plus database include paths db.php and ./include/db_conn.php. No hardcoded external IPs, domains, or remote URLs are present.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.