A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. The exploit is now public and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 19 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. The exploit is now public and may be used.
Title PHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery
First Time appeared Phpems
Phpems phpems
Weaknesses CWE-918
CPEs cpe:2.3:a:phpems:phpems:*:*:*:*:*:*:*:*
Vendors & Products Phpems
Phpems phpems
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-19T12:45:14.558Z

Reserved: 2026-04-18T19:47:53.569Z

Link: CVE-2026-6573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-19T13:16:46.187

Modified: 2026-04-19T13:16:46.187

Link: CVE-2026-6573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-19T15:15:15Z

Weaknesses