CVE-2026-6573 Details
Description
A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.master.php of the component Instant Exam Creation Handler. The manipulation of the argument uploadfile results in server-side request forgery. The attack can be executed remotely. The exploit is now public and may be used.
A server-side request forgery (SSRF) vulnerability has been identified in PHPEMS version 11.0. This issue arises in the Instant Exam Creation feature, specifically within the 'temppage' function of the '/app/exam/controller/exams.master.php' file. The vulnerability allows remote attackers to manipulate the 'uploadfile' parameter, which is passed to 'fopen()' without proper validation. As a result, attackers can send HTTP URLs that the server will fetch, potentially leading to unauthorized access of internal services or network probing.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 19, 2026CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/789990 | [email protected] | Technical Description |
| https://vuldb.com/vuln/358207 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/358207/cti | [email protected] | AdvisoryPermission Required |
| https://vulnplus-note.wetolink.com/share/1QZ4NE0oTRIc | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PHPEMS | 11.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 19, 2026 | New CVE Received | [email protected] |
Volerion