Improper authorization control for web services In nabeel/phpvms

Description

phpVMS has an /importer authorization bypass causing full database wipe

Security Advisory: Unauthenticated Access to Legacy Import Feature

Severity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer

Summary

A critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational.

Impact

A remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:

    Data loss

    Service disruption

No authentication was required.

Remediation

    Update immediately to the latest patched version

    If unable to update:

      The release link has instructions on how to fix it (it's a one-line fix to comment out the routes)

Affected Versions

    Affected: phpVMS 7.x ≤ 7.0.5

    Not affected: phpVMS >= 7.0.6, v8 (feature removed from public access)

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions