Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52m5-qhx2-x9w6

Опубликовано: 11 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 

'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 

'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.

EPSS

Процентиль: 9%
0.00031
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.

EPSS

Процентиль: 9%
0.00031
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-89