github.com
https://github.com/k0xx11/bug_report/blob/main/vendors/oretnom23/online-fire-reporting-system/SQLi-10.md CVE-2022-31984
HIGHNuclei
online_fire_reporting_system_project online_fire_reporting_system Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2022-31984 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
online_fire_reporting_systemBrowse online_fire_reporting_system_project / online_fire_reporting_system | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHOnline Fire Reporting System v1.0 - SQL injectionCVSS 7.2
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, or manipulation of the database.
Remediation
To remediate this issue, ensure that all user-supplied input is properly validated and sanitized before being used in SQL queries.
WeaknessesCWE-89
Authorstheamanrawat
Template tagscve2022cvesqlionline-fire-reportingonline_fire_reporting_system_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:online_fire_reporting_system_project:online_fire_reporting_system:1.0:*:*:*:*:*:*:*
https://github.com/debug601/bug_report/blob/main/vendors/oretnom23/online-fire-reporting-system/SQLi-10.md https://www.sourcecodester.com/php/15346/online-fire-reporting-system-phpoop-free-source-code.html https://nvd.nist.gov/vuln/detail/CVE-2022-31984
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-31984