First published: Tue Jun 14 2022(Updated: )
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Fire Reporting System Project Online Fire Reporting System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Online Fire Reporting System is CVE-2022-31415.
CVE-2022-31415 has a severity rating of 6.5, which is categorized as medium.
The affected software is Online Fire Reporting System v1.0.
The CWE ID for CVE-2022-31415 is CWE-89 (SQL Injection).
To fix the SQL injection vulnerability in Online Fire Reporting System v1.0, it is recommended to sanitize and validate user input, use prepared statements or parameterized queries, and implement proper input validation and output encoding.