Description
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
References
https://researchinthebin.org/posts/ofrs-sql-injection/
ExploitThird Party Advisory
https://researchinthebin.org/posts/ofrs-sql-injection/
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-06-14T03:15:08.153Z
4 years agoLast modified
2026-06-17T04:45:26.040Z
2 months ago