PHPGurukul Online Fire Reporting System
cpe:2.3:a:phpgurukul:online_fire_reporting_system:*:*:*:*:*:*:*
- 1.2
A critical SQL injection vulnerability has been identified in PHPGurukul Online Fire Reporting System version 1.2. The issue resides in the admin manage-teams.php file, where the teamid parameter can be manipulated to execute unauthorized SQL commands. This vulnerability can be exploited remotely, and details of the exploit are publicly available.
Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries, potentially leading to unauthorized data access or modification.
The vulnerability can be reproduced by sending a GET request to the admin/manage-teams.php file with a crafted teamid parameter. The SQL injection can be verified by using a payload that, for example, causes a time-based delay in the response, indicating that the injected SQL query was executed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.