PT-2023-32730 · Phpems · Phpems

Glzjin

·

Published

2023-12-10

·

Updated

2024-05-17

·

CVE-2023-6654

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHPEMS versions 6.x through 9.0
Description A critical vulnerability was found in the library lib/session.cls.php of the component Session Data Handler, affecting an unknown functionality. The manipulation leads to deserialization and can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For PHPEMS versions 6.x through 9.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2023-6654
GHSA-5RV2-VVMF-F7W8

Affected Products

Phpems