A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit is now public and may be used.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Dec 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit is now public and may be used. | |
| Title | PHPEMS Coupon race condition | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-30T09:32:07.221Z
Reserved: 2025-12-29T08:16:05.639Z
Link: CVE-2025-15242
No data.
Status : Received
Published: 2025-12-30T10:15:51.610
Modified: 2025-12-30T10:15:51.610
Link: CVE-2025-15242
No data.
OpenCVE Enrichment
No data.