CVE-2025-15242

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit is now public and may be used.
References
Link Resource
https://byebydoggy.github.io/post/2025/1229-phpems-coupon-recharge-race-condition-poc/ Exploit Mitigation Third Party Advisory
https://vuldb.com/?ctiid.338632 Permissions Required VDB Entry
https://vuldb.com/?id.338632 Third Party Advisory VDB Entry
https://vuldb.com/?submit.725661 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpems:phpems:*:*:*:*:*:*:*:*

History

07 Jan 2026, 21:40

Type Values Removed Values Added
References () https://byebydoggy.github.io/post/2025/1229-phpems-coupon-recharge-race-condition-poc/ - () https://byebydoggy.github.io/post/2025/1229-phpems-coupon-recharge-race-condition-poc/ - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.338632 - () https://vuldb.com/?ctiid.338632 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.338632 - () https://vuldb.com/?id.338632 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.725661 - () https://vuldb.com/?submit.725661 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:phpems:phpems:*:*:*:*:*:*:*:*
First Time Phpems phpems
Phpems

30 Dec 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 10:15

Updated : 2026-01-07 21:40


NVD link : CVE-2025-15242

Mitre link : CVE-2025-15242

CVE.ORG link : CVE-2025-15242


JSON object : View

Products Affected

phpems

  • phpems
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')