PHPGurukul Online Fire Reporting System SQL Injection Vulnerability in Manage Teams Admin File

Vulnerability

A critical SQL injection vulnerability has been identified in PHPGurukul Online Fire Reporting System version 1.2. The issue resides in the admin manage-teams.php file, where the teamid parameter can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, and details of the exploit are publicly available.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries, potentially leading to unauthorized data access or modification.

Reproduction

The vulnerability can be reproduced by sending a GET request to the admin/manage-teams.php file with a crafted teamid parameter. The SQL injection can be verified by using a payload that, for example, causes a time-based delay in the response, indicating that the injected SQL query was executed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.