Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fv26-4939-62fh | phpVMS has an /importer authorization bypass causing full database wipe |
Tue, 12 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpvms
Phpvms phpvms |
|
| Vendors & Products |
Phpvms
Phpvms phpvms |
Sat, 09 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been patched in version 7.0.6. | |
| Title | phpvms: /importer authorization bypass causing full database wipe | |
| Weaknesses | CWE-284 CWE-306 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T18:31:04.998Z
Reserved: 2026-04-28T17:26:12.084Z
Link: CVE-2026-42569
Updated: 2026-05-12T13:54:09.182Z
Status : Deferred
Published: 2026-05-09T20:16:29.127
Modified: 2026-05-13T14:54:50.290
Link: CVE-2026-42569
No data.
OpenCVE Enrichment
Updated: 2026-05-15T14:45:16Z
Github GHSA