Description
A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used.
References
https://byebydoggy.github.io/post/2025/1229-phpems-points-race-condition-poc/
ExploitMitigationThird Party Advisory
https://vuldb.com/?ctiid.338634
Permissions RequiredVDB Entry
Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.725727
Third Party AdvisoryVDB Entry
CVSS impact metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
3.7 · Low
Information
Source identifier
Vulnerability status
Analyzed
Published
2025-12-30T11:15:54.730Z
2 weeks agoLast modified
2026-01-07T21:41:37.437Z
1 week ago