Phpipam

Phpipam

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 17.08.2026 20:36:01
  • Zuletzt bearbeitet 20.08.2026 16:18:00

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is us...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 04.07.2026 06:54:21
  • Zuletzt bearbeitet 06.07.2026 19:43:54

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 15.03.2026 19:32:12
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin/sections/edit-result.php of the component Section Handler. Executing a manipulation of the argument subnetOrdering can lead to sq...

  • EPSS 0.26%
  • Veröffentlicht 09.12.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 02:17:18

Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.

  • EPSS 0.2%
  • Veröffentlicht 08.12.2025 00:00:00
  • Zuletzt bearbeitet 10.12.2025 17:36:31

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump...

  • EPSS 0.23%
  • Veröffentlicht 31.03.2025 13:15:42
  • Zuletzt bearbeitet 23.04.2025 18:32:54

phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.03.2025 10:11:07
  • Zuletzt bearbeitet 01.04.2025 20:35:45

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view th...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.03.2025 10:10:58
  • Zuletzt bearbeitet 01.04.2025 20:35:36

A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request and includes that data within the immediate response in an uns...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 20.03.2025 10:10:32
  • Zuletzt bearbeitet 28.05.2025 20:36:18

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' section under 'Administration' where an attacker can inject malicious scripts into the 'Name' and 'Descript...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.03.2025 10:10:29
  • Zuletzt bearbeitet 28.05.2025 20:35:42

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can l...