VulnerabilityAnalyzed
CVE-2025-15244
A vulnerability has been found in PHPEMS up to 11.0.
LOW 2.9EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 2.9 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- phpems/phpems
- Source
- cna@vuldb.com
References
- https://byebydoggy.github.io/post/2025/1229-phpems-points-race-condition-poc/Exploit, Mitigation, Third Party Advisory
- https://vuldb.com/?ctiid.338634Permissions Required, VDB Entry
- https://vuldb.com/?id.338634Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.725727Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.