Stored Cross Site Scripting in Online Fire Reporting System by PHPGurukul
CVE-2025-40695
5.1MEDIUM
Key Information:
- Vendor
PHPgurukul
- Vendor
- CVE Published:
- 11 September 2025
What is CVE-2025-40695?
The Online Fire Reporting System, version 1.2 by PHPGurukul, is vulnerable to Stored Cross Site Scripting (XSS). This vulnerability arises from improper validation of user inputs in the 'remark', 'status', and 'takeaction' parameters via POST requests at the endpoint '/ofrs/admin/request-details.php'. An attacker could craft a malicious payload that, when submitted, would be stored and later executed within the session of an authenticated user. This could potentially allow the attacker to gain unauthorized access to sensitive information, as the user's cookie session details may be compromised.
Affected Version(s)
Online Fire Reporting System 1.2