PHPGurukul Online Fire Reporting System Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in PHPGurukul's Online Fire Reporting System version 1.2. This vulnerability arises from inadequate validation of user inputs, allowing for both reflected and stored authenticated XSS. The issue is present in the '/ofrs/admin/edit-team.php' endpoint, where the 'tname' parameter via GET and the 'teamleadname', 'teammember', and 'teamname' parameters via POST are vulnerable. Exploitation of this vulnerability could enable a remote user to send a specially crafted query to an authenticated user, potentially leading to the theft of session cookie details.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Added: Sep 11, 2025, 12:20 PM
Updated: Sep 11, 2025, 5:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
3.0
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.