CVE-2024-10722
- EPSS 0.34%
- Veröffentlicht 20.03.2025 10:10:29
- Zuletzt bearbeitet 28.05.2025 20:35:42
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can l...
CVE-2024-10719
- EPSS 0.33%
- Veröffentlicht 20.03.2025 10:10:07
- Zuletzt bearbeitet 28.05.2025 20:34:18
A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerability allows an attacker to inject malicious scripts via the 'option' parameter in the POST request to...
CVE-2024-10718
- EPSS 0.33%
- Veröffentlicht 20.03.2025 10:10:07
- Zuletzt bearbeitet 27.06.2025 15:29:49
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue ...
CVE-2024-10724
- EPSS 0.34%
- Veröffentlicht 20.03.2025 10:09:30
- Zuletzt bearbeitet 28.05.2025 20:34:37
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The ...
CVE-2024-10723
- EPSS 0.34%
- Veröffentlicht 20.03.2025 10:09:23
- Zuletzt bearbeitet 28.05.2025 20:34:48
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user...
CVE-2024-10725
- EPSS 0.34%
- Veröffentlicht 20.03.2025 10:09:15
- Zuletzt bearbeitet 28.05.2025 20:34:29
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affe...
CVE-2024-0787
- EPSS 0.45%
- Veröffentlicht 15.11.2024 11:15:09
- Zuletzt bearbeitet 19.11.2024 15:53:59
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines...
CVE-2022-1226
- EPSS 0.4%
- Veröffentlicht 15.11.2024 11:15:07
- Zuletzt bearbeitet 19.11.2024 15:30:53
A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects the import Data set feature via a spreadsheet file uplo...
CVE-2024-41358
- EPSS 1.59%
- Veröffentlicht 29.08.2024 20:15:08
- Zuletzt bearbeitet 26.01.2026 16:15:57
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
CVE-2024-41354
- EPSS 0.33%
- Veröffentlicht 26.07.2024 17:15:12
- Zuletzt bearbeitet 23.04.2025 18:33:52
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php