phpVMS Unauthenticated Access to Legacy Import Feature Vulnerability

Vulnerability

A critical vulnerability exists in phpVMS versions prior to 7.0.6, allowing unauthenticated users to access a deprecated import feature. This access could trigger internal processes that modify or delete application data, leading to data loss and service disruption.

Impact

Exploitation of this vulnerability could cause unauthorized data modification or deletion, with potential for significant data loss and disruption of service.

Remediation

Users should update to phpVMS version 7.0.7 or later. If an immediate update is not possible, the vulnerability can be mitigated by commenting out the importer route in the RouteServiceProvider.

Added: May 9, 2026, 8:24 PM
Updated: May 9, 2026, 8:24 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.0
exploitability
9.0
remediation
7.9
relevance
7.9
threat
3.2
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.