Severity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer
A critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational.
A remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required.
7.0.6Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:LI:HA:H9.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H