CVE-2022-31978: SQL Injection
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=deleteinquiry.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31978?
CVE-2022-31978 is a vulnerability in the Online Fire Reporting System v1.0 that allows SQL Injection via the /ofrs/classes/Master.php?f=delete_inquiry endpoint.
How severe is CVE-2022-31978?
CVE-2022-31978 has a severity of critical, with a CVSS score of 9.8.
How does CVE-2022-31978 affect Online Fire Reporting System v1.0?
CVE-2022-31978 allows an attacker to perform SQL Injection attacks on the Online Fire Reporting System v1.0 through the /ofrs/classes/Master.php?f=delete_inquiry endpoint.
How can I fix CVE-2022-31978 in the Online Fire Reporting System v1.0?
To fix CVE-2022-31978, it is recommended to update the Online Fire Reporting System v1.0 to a secure version that addresses the SQL Injection vulnerability.
What is CWE-89?
CWE-89 is a common weakness enumeration category that refers to SQL Injection vulnerabilities.