cbcvebase.

Phpgurukul Online Fire Reporting System vulnerabilities

32 known vulnerabilities affecting phpgurukul/online_fire_reporting_system.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH12MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2025-40687P3CRITICALCVSS 9.8v1.22025-09-11
CVE-2025-40687 [CRITICAL] CWE-89 CVE-2025-40687: SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attac SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.
nvd
CVE-2025-40692P3CRITICALCVSS 9.8v1.22025-09-11
CVE-2025-40692 [CRITICAL] CWE-89 CVE-2025-40692: SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attac SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'.
nvd
CVE-2025-40691P3CRITICALCVSS 9.8v1.22025-09-11
CVE-2025-40691 [CRITICAL] CWE-89 CVE-2025-40691: SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attac SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.
nvd
CVE-2025-40689P3CRITICALCVSS 9.8v1.22025-09-11
CVE-2025-40689 [CRITICAL] CWE-89 CVE-2025-40689: SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attac SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'.
nvd
CVE-2025-40690P3CRITICALCVSS 9.8v1.22025-09-11
CVE-2025-40690 [CRITICAL] CWE-89 CVE-2025-40690: SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attac SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.
nvd
CVE-2025-40696P4MEDIUMCVSS 5.4v1.22025-09-11
CVE-2025-40696 [MEDIUM] CWE-79 CVE-2025-40696: Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a s Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This vulnerability could allow a remote user to send a specially crafted query
nvd
CVE-2025-40694P4MEDIUMCVSS 5.4v1.22025-09-11
CVE-2025-40694 [MEDIUM] CWE-79 CVE-2025-40694: Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a s Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'. This vulnerability could allow a remote user to send a specially crafted q
nvd
CVE-2025-40695P4MEDIUMCVSS 5.4v1.22025-09-11
CVE-2025-40695 [MEDIUM] CWE-79 CVE-2025-40695: Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a s Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint '/ofrs/admin/request-details.php'. This vulnerability could allow a remote user to send a specially cra
nvd
CVE-2025-40693P4MEDIUMCVSS 5.4v1.22025-09-11
CVE-2025-40693 [MEDIUM] CWE-79 CVE-2025-40693: Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a r Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability c
nvd
CVE-2023-36941P4MEDIUMCVSS 6.1v1.22023-07-27
CVE-2023-36941 [MEDIUM] CWE-79 CVE-2023-36941: A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.
nvd
CVE-2023-36942P4MEDIUMCVSS 6.1v1.22023-07-27
CVE-2023-36942 [MEDIUM] CWE-79 CVE-2023-36942: A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.
nvd
CVE-2023-36940P4MEDIUMCVSS 4.8v1.22023-07-10
CVE-2023-36940 [MEDIUM] CWE-79 CVE-2023-36940: Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and My Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.
nvd
Phpgurukul Online Fire Reporting System vulnerabilities | cvebase