PHPEMS Server-Side Request Forgery Vulnerability in Instant Exam Creation Component

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in PHPEMS version 11.0. This issue arises in the Instant Exam Creation feature, specifically within the 'temppage' function of the '/app/exam/controller/exams.master.php' file. The vulnerability allows remote attackers to manipulate the 'uploadfile' parameter, which is passed to 'fopen()' without proper validation. As a result, attackers can send HTTP URLs that the server will fetch, potentially leading to unauthorized access of internal services or network probing.

Impact

Exploitation of this vulnerability allows for server-side request forgery, where the server is tricked into making requests to internal resources or services, which could be further exploited or used for reconnaissance.

Added: Apr 19, 2026, 1:19 PM
Updated: Apr 19, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.4
exploitability
6.8
remediation
0.0
relevance
6.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.