SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via
'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.
'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 11 Sep 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. | |
Title | SQL injection in PHPGurukul Online Fire Reporting System | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-11T11:18:37.432Z
Reserved: 2025-04-16T08:38:17.111Z
Link: CVE-2025-40687

No data.

Status : Received
Published: 2025-09-11T12:15:34.740
Modified: 2025-09-11T12:15:34.740
Link: CVE-2025-40687

No data.

No data.