Beveiligingsadvies

CVE-2026-6573

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-19 12:45:14
Laatst bijgewerkt 2026-04-20 15:19:11
Toegewezen door VulDB
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. The exploit is now public and may be used.