SQL Injection Vulnerability in PHPGurukul Online Fire Reporting System 1.2
CVE-2025-7562
5.3MEDIUM
What is CVE-2025-7562?
A vulnerability in the PHPGurukul Online Fire Reporting System 1.2 exposes the system to SQL injection via the /admin/new-requests.php file. By manipulating the 'teamid' argument, attackers can execute unauthorized SQL commands, potentially compromising the database. This flaw can be exploited remotely, allowing malicious actors to exploit it over the internet. It is critical for users of this system to apply security measures to mitigate these threats as the exploit is publicly known.
Affected Version(s)
Online Fire Reporting System 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.