CVE 9.3 CRITICAL

SQL injection in PHPGurukul Online Fire Reporting System_CVE-2025-40687

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 

'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.

Basic Information

ID CVE-2025-40687
Source INCIBE
Published Sep 11, 2025 at 11:15
Modified Sep 11, 2025 at 11:18

Affected Product

Vendor PHPGurukul
Product Online Fire Reporting System
Version 1.2
Affected Versions PHPGurukul Online Fire Reporting System 1.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.