CVE-2025-40690: SQL injection in PHPGurukul Online Fire Reporting System
Published Sep 11, 2025
·Updated
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.
Affected Software
2 affected components
Phpgurukul Online Fire Reporting System
Phpgurukul Online Fire Reporting System=1.2
Event History
Sep 11, 2025
CVE Published
via MITRE·11:23 AM
Data Sourced
via MITRE·11:23 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-40690?
CVE-2025-40690 is classified as a high-severity SQL Injection vulnerability.
2
How do I fix CVE-2025-40690?
To fix CVE-2025-40690, it is recommended to sanitize and validate all user inputs, particularly the 'teamid' parameter.
3
What systems are affected by CVE-2025-40690?
CVE-2025-40690 affects the Online Fire Reporting System v1.2 developed by PHPGurukul.
4
What can an attacker do using CVE-2025-40690?
Using CVE-2025-40690, an attacker can retrieve, create, update, and delete data in the database via the vulnerable endpoint.
5
Is there a patch available for CVE-2025-40690?
As of now, there is no publicly available patch for CVE-2025-40690, so immediate mitigation steps should be taken.