Description


A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit is now public and may be used.

Related CPE's


Vulnerable

References



https://vuldb.com/?ctiid.338632

Permissions RequiredVDB Entry

https://vuldb.com/?id.338632

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.725661

Third Party AdvisoryVDB Entry

Weaknesses



CWE-362

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

3.1 · Low

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-12-30T10:15:51.610Z

2 weeks ago

Last modified

2026-01-07T21:40:35.350Z

1 week ago