PHPGurukul Online Fire Reporting System all-requests.php sql injection

CVE Details

Basic Information

Title PHPGurukul Online Fire Reporting System all-requests.php sql injection
Type cve
Published 2025-07-14T07:14:06.498Z
Modified 2025-07-14T07:14:06.498Z

Product Information

Vendor PHPGurukul
Product Online Fire Reporting System
Version 1.2

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A SQL injection vulnerability in PHPGurukul Online Fire Reporting System 1.2 allows remote attackers to inject malicious SQL code via the ‘teamid’ argument in /admin/all-requests.php. This vulnerability is critical and can lead to unauthorized data access and manipulation.
AI Severity Medium
AI Vendor PHPGurukul
AI Product PHPGurukul Online Fire Reporting System
AI Version 1.2

Affected Products

  • PHPGurukul Online Fire Reporting System 1.2

Additional Information

CWE List CWE-89, CWE-74
Source VulDB

Description

A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerability affects unknown code of the file /admin/all-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.