CVE-2026-6573 is a server-side request forgery (SSRF) vulnerability in PHPEMS 11.0, specifically within the temppage function of the Instant Exam Creation Handler component located at /app/exam/controller/exams.master.php. The flaw can be exploited by manipulating the uploadfile parameter, allowing unauthenticated remote attackers to perform arbitrary server-side requests. The vulnerability is assigned a CVSS 3.1 score of 6.3 (MEDIUM) with a network attack vector and low complexity, requiring only low-level privileges to exploit. The potential impact includes confidentiality and integrity compromise at the application level, with limited availability impact. Public exploit code is currently available for this vulnerability, and it maintains an active status on security tracking lists, indicating ongoing community attention and potential use in targeted attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | PHPEMS | 11.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.