SQL Injection Vulnerability in PHPGurukul Online Fire Reporting System
CVE-2025-7584
5.3MEDIUM
What is CVE-2025-7584?
A vulnerability present in PHPGurukul Online Fire Reporting System version 1.2 allows for SQL injection via the /admin/add-team.php file. This vulnerability can be exploited remotely by manipulating the 'teammember' argument, leading to unauthorized access to the underlying database. Given its public disclosure, it poses a threat to users who have not yet mitigated this issue.
Affected Version(s)
Online Fire Reporting System 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.