CVE-2025-40690

CWE-89SQL Injection3 documents3 sources
Severity
9.3CRITICAL
EPSS
0.0%
top 87.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11

Description

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
GHSA
GHSA-fj6q-c6x7-q7w3: SQL Injection in Online Fire Reporting System v12025-09-11
CVEList
SQL injection in PHPGurukul Online Fire Reporting System2025-09-11
CVE-2025-40690 (CRITICAL CVSS 9.3) | SQL Injection in Online Fire Report | cvebase.io