Stored Cross Site Scripting in Online Fire Reporting System by PHPGurukul
CVE-2025-40695

5.1MEDIUM

Key Information:

Vendor

PHPgurukul

Vendor
CVE Published:
11 September 2025

What is CVE-2025-40695?

The Online Fire Reporting System, version 1.2 by PHPGurukul, is vulnerable to Stored Cross Site Scripting (XSS). This vulnerability arises from improper validation of user inputs in the 'remark', 'status', and 'takeaction' parameters via POST requests at the endpoint '/ofrs/admin/request-details.php'. An attacker could craft a malicious payload that, when submitted, would be stored and later executed within the session of an authenticated user. This could potentially allow the attacker to gain unauthorized access to sensitive information, as the user's cookie session details may be compromised.

Affected Version(s)

Online Fire Reporting System 1.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.
CVE-2025-40695 : Stored Cross Site Scripting in Online Fire Reporting System by PHPGurukul