Phpipam

Phpipam

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.45%
  • Veröffentlicht 04.02.2023 13:15:12
  • Zuletzt bearbeitet 21.11.2024 07:37:36

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.

Exploit
  • EPSS 1.53%
  • Veröffentlicht 04.02.2023 13:15:12
  • Zuletzt bearbeitet 13.02.2026 17:16:09

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.

  • EPSS 0.55%
  • Veröffentlicht 02.11.2022 20:15:11
  • Zuletzt bearbeitet 21.11.2024 07:20:21

A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation lea...

Exploit
  • EPSS 1.16%
  • Veröffentlicht 03.10.2022 16:15:13
  • Zuletzt bearbeitet 21.11.2024 07:23:14

phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 04.04.2022 11:15:08
  • Zuletzt bearbeitet 21.11.2024 06:40:17

Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 04.04.2022 11:15:08
  • Zuletzt bearbeitet 21.11.2024 06:40:17

Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 04.04.2022 11:15:08
  • Zuletzt bearbeitet 24.02.2026 20:18:04

Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Exploit
  • EPSS 0.92%
  • Veröffentlicht 25.03.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:34:03

phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

Exploit
  • EPSS 25.24%
  • Veröffentlicht 19.01.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:47:52

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

Exploit
  • EPSS 0.62%
  • Veröffentlicht 19.01.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:47:52

PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.