CVE-2025-40691
11.09.2025, 12:15
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.
Awaiting analysis
This vulnerability is currently awaiting analysis.