Vulnerability Details CVE-2024-1353
A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the file app/weixin/controller/index.api.php. The manipulation of the argument picurl leads to deserialization. The exploit has been disclosed to the public and may be used. VDB-253226 is the identifier assigned to this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.6%
CVSS Severity
CVSS v3 Score 6.3
CVSS v2 Score 5.8
Products affected by CVE-2024-1353
-
cpe:2.3:a:phpems:phpems:-
-
cpe:2.3:a:phpems:phpems:1.0