First published: Wed Jun 01 2022(Updated: )
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Fire Reporting System Project Online Fire Reporting System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31978 is a vulnerability in the Online Fire Reporting System v1.0 that allows SQL Injection via the /ofrs/classes/Master.php?f=delete_inquiry endpoint.
CVE-2022-31978 has a severity of critical, with a CVSS score of 9.8.
CVE-2022-31978 allows an attacker to perform SQL Injection attacks on the Online Fire Reporting System v1.0 through the /ofrs/classes/Master.php?f=delete_inquiry endpoint.
To fix CVE-2022-31978, it is recommended to update the Online Fire Reporting System v1.0 to a secure version that addresses the SQL Injection vulnerability.
CWE-89 is a common weakness enumeration category that refers to SQL Injection vulnerabilities.