Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40687


SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.


Published

2025-09-11T12:15:34.740

Last Modified

2025-09-12T15:32:29.880

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application phpgurukul online_fire_reporting_system 1.2 Yes

References