CVE-2023-41580
- EPSS 0.56%
- Veröffentlicht 02.10.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:21:19
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via ...
CVE-2023-4965
- EPSS 0.16%
- Veröffentlicht 14.09.2023 20:15:12
- Zuletzt bearbeitet 21.11.2024 08:36:21
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack m...
CVE-2023-24657
- EPSS 2.88%
- Veröffentlicht 08.03.2023 06:15:44
- Zuletzt bearbeitet 05.03.2025 19:15:29
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
CVE-2023-1212
- EPSS 0.1%
- Veröffentlicht 07.03.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:38:40
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVE-2023-1211
- EPSS 0.33%
- Veröffentlicht 07.03.2023 00:15:09
- Zuletzt bearbeitet 16.02.2026 15:18:33
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVE-2023-0678
- EPSS 67.62%
- Veröffentlicht 04.02.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 07:37:36
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2023-0677
- EPSS 0.33%
- Veröffentlicht 04.02.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 07:37:36
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
CVE-2023-0676
- EPSS 0.97%
- Veröffentlicht 04.02.2023 13:15:12
- Zuletzt bearbeitet 13.02.2026 17:16:09
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVE-2022-3845
- EPSS 0.31%
- Veröffentlicht 02.11.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:20:21
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation lea...
CVE-2022-41443
- EPSS 1.49%
- Veröffentlicht 03.10.2022 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:23:14
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.