9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via
'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.
'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.
Basic Information
ID
CVE-2025-40687
Source
INCIBE
Published
Sep 11, 2025 at 11:15
Modified
Sep 11, 2025 at 11:18
Affected Product
Vendor
PHPGurukul
Product
Online Fire Reporting System
Version
1.2
Affected Versions
PHPGurukul Online Fire Reporting System 1.2