Stored Cross Site Scripting in Online Fire Reporting System by PHPGurukul
CVE-2025-40695
Key Information:
- Vendor
PHPgurukul
- Vendor
- CVE Published:
- 11 September 2025
What is CVE-2025-40695?
The Online Fire Reporting System, version 1.2 by PHPGurukul, is vulnerable to Stored Cross Site Scripting (XSS). This vulnerability arises from improper validation of user inputs in the 'remark', 'status', and 'takeaction' parameters via POST requests at the endpoint '/ofrs/admin/request-details.php'. An attacker could craft a malicious payload that, when submitted, would be stored and later executed within the session of an authenticated user. This could potentially allow the attacker to gain unauthorized access to sensitive information, as the user's cookie session details may be compromised.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Online Fire Reporting System 1.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
