PT-2025-37171 · Unknown · Online Fire Reporting System

Rafael Pedrero

·

Published

2025-09-11

·

Updated

2025-09-16

·

CVE-2025-40689

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Online Fire Reporting System version 1.2
Description: The Online Fire Reporting System is susceptible to SQL Injection attacks. An attacker can potentially retrieve, create, update, and delete database information through the remark, status, and requestid parameters in the /ofrs/admin/request-details.php API endpoint.
Recommendations: Apply input validation and sanitization to the remark, status, and requestid parameters in the /ofrs/admin/request-details.php endpoint. Consider using parameterized queries or prepared statements to prevent SQL Injection.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-40689

Affected Products

Online Fire Reporting System