Improper authorization control for web services In nabeel/phpvms
Description
phpVMS has an /importer authorization bypass causing full database wipe
Security Advisory: Unauthenticated Access to Legacy Import Feature
Severity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer
Summary
A critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational.
Impact
A remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
Data loss
Service disruption
No authentication was required.
Remediation
Update immediately to the latest patched version
If unable to update:
The release link has instructions on how to fix it (it's a one-line fix to comment out the routes)
Affected Versions
Affected: phpVMS 7.x ≤ 7.0.5
Not affected: phpVMS >= 7.0.6, v8 (feature removed from public access)
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 7.0.6 |
Aliases
References