phpVMS
cpe:2.3:a:phpvms:phpvms:*:*:*:*:*:*:*
- <= 7.0.5
A critical vulnerability exists in phpVMS versions prior to 7.0.6, allowing unauthenticated users to access a deprecated import feature. This access could trigger internal processes that modify or delete application data, leading to data loss and service disruption.
Exploitation of this vulnerability could cause unauthorized data modification or deletion, with potential for significant data loss and disruption of service.
Users should update to phpVMS version 7.0.7 or later. If an immediate update is not possible, the vulnerability can be mitigated by commenting out the importer route in the RouteServiceProvider.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.