Description
A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247357 was assigned to this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3118 | A vulnerability classified as critical was found in PHPEMS 6.x/7.x/8.x/9.0. Affected by this vulnerability is an unknown functionality in the library lib/session.cls.php of the component Session Data Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247357 was assigned to this vulnerability. |
Github GHSA |
GHSA-5rv2-vvmf-f7w8 | PHPEMS Deserialization of Untrusted Data vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-28T15:18:27.567Z
Reserved: 2023-12-09T20:39:55.056Z
Link: CVE-2023-6654
Updated: 2024-08-02T08:35:14.822Z
Status : Modified
Published: 2023-12-10T15:15:07.160
Modified: 2024-11-21T08:44:17.837
Link: CVE-2023-6654
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA