Back

MEDIUM

Cross Site Scripting in PHPGurukul Online Fire Reporting System

Published Sep 11, 2025

Description

Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname'

parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Sep 11, 2025
Updated Sep 11, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Sep 11, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published Sep 11, 2025
Updated Sep 11, 2025
Exploited since n/a
EUVD-2025-28896