PT-2025-37179 · Unknown · Online Fire Reporting System

Rafael Pedrero

·

Published

2025-09-11

·

Updated

2025-09-12

·

CVE-2025-40695

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Online Fire Reporting System version 1.2
Description: The Online Fire Reporting System contains a stored cross-site scripting (XSS) issue. The lack of proper validation of user inputs for the remark, status, and takeaction parameters via POST requests at the /ofrs/admin/request-details.php endpoint allows a remote user to send a specially crafted query to an authenticated user and potentially steal cookie session details.
Recommendations: Apply appropriate input validation and sanitization techniques to the remark, status, and takeaction parameters in the /ofrs/admin/request-details.php endpoint.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-40695

Affected Products

Online Fire Reporting System