CVE-2025-15242

low
Published 2025-12-30 · Modified 2026-04-29
CVSS v3
3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2
2.1
VIR risk
3.1

Description

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit is now public and may be used.

Predictions

Exploit likelihood
42%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://byebydoggy.github.io/post/2025/1229-phpems-coupon-recharge-race-condition-poc/

Application impact

VendorProductVersionsFixed
phpemsphpems{"endIncluding":"11.0"}

References

CWEs

CWE-362

Verify integrity in audit chain (admin only). AS-IS.