Description
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely.
Problem types
Timeline
| 2026-01-01: | Advisory disclosed |
| 2026-01-01: | VulDB entry created |
| 2026-01-01: | VulDB entry last update |
Credits
byebyedoggy (VulDB User)
References
vuldb.com/?id.339325 (VDB-339325 | PHPEMS cross-site request forgery)
vuldb.com/?ctiid.339325 (VDB-339325 | CTI Indicators (IOB, IOC))
vuldb.com/?submit.728314 (Submit #728314 | PHPEMS <=11.0 Cross-Site Request Forgery)
byebydoggy.github.io/post/2025/1231-phpems-csrf-poc/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.