CVE-2025-40690
🟠 Łataj w tym tygodniu
Wstrzyknięcie SQL w Online Fire Reporting System umożliwia atakującemu manipulację bazą danych.
CVSS
9.8
EPSS
0.3%
Exploit
none
Vendor
phpgurukul
Opis źródłowy (NVD)
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.
sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-09-11 12:15:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje