CVE-2025-40691: SQL injection in PHPGurukul Online Fire Reporting System
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via
'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40691?
CVE-2025-40691 has been classified with a high severity level due to its potential for unauthorized database access.
How do I fix CVE-2025-40691?
To fix CVE-2025-40691, it is recommended to sanitize and validate all user inputs, particularly the 'todate' parameter.
What systems are affected by CVE-2025-40691?
CVE-2025-40691 affects version 1.2 of the Online Fire Reporting System by PHPGurukul.
What type of vulnerability is CVE-2025-40691?
CVE-2025-40691 is an SQL Injection vulnerability that allows attackers to manipulate database queries.
What could attackers do with CVE-2025-40691?
With CVE-2025-40691, attackers could retrieve, create, update, or delete data in the database using the vulnerable endpoint.