Description
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit is now public and may be used.
Problem types
Timeline
| 2025-12-29: | Advisory disclosed |
| 2025-12-29: | VulDB entry created |
| 2025-12-29: | VulDB entry last update |
Credits
byebyedoggy (VulDB User)
References
vuldb.com/?id.338632 (VDB-338632 | PHPEMS Coupon race condition)
vuldb.com/?ctiid.338632 (VDB-338632 | CTI Indicators (IOB, IOC))
vuldb.com/?submit.725661 (Submit #725661 | PHPEMS <=11.0 Race Condition)
byebydoggy.github.io/...-coupon-recharge-race-condition-poc/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.