PHPEMS
cpe:2.3:a:phpems:phpems:*:*:*:*:*:*:*
- 11.0
A server-side request forgery (SSRF) vulnerability has been identified in PHPEMS version 11.0. This issue arises in the Instant Exam Creation feature, specifically within the 'temppage' function of the '/app/exam/controller/exams.master.php' file. The vulnerability allows remote attackers to manipulate the 'uploadfile' parameter, which is passed to 'fopen()' without proper validation. As a result, attackers can send HTTP URLs that the server will fetch, potentially leading to unauthorized access of internal services or network probing.
Exploitation of this vulnerability allows for server-side request forgery, where the server is tricked into making requests to internal resources or services, which could be further exploited or used for reconnaissance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.