CVE-2022-23045
- EPSS 0.62%
- Veröffentlicht 19.01.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:52
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.
CVE-2021-35438
- EPSS 1.02%
- Veröffentlicht 23.06.2021 15:15:08
- Zuletzt bearbeitet 13.02.2026 17:16:09
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
CVE-2020-13225
- EPSS 0.61%
- Veröffentlicht 20.05.2020 04:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:50
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.
CVE-2020-7988
- EPSS 0.73%
- Veröffentlicht 04.03.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:08
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requi...
CVE-2019-16696
- EPSS 1.88%
- Veröffentlicht 22.09.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:31:00
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
CVE-2019-16695
- EPSS 1.88%
- Veröffentlicht 22.09.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16694
- EPSS 1.88%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
CVE-2019-16693
- EPSS 4.34%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 16.04.2025 15:15:44
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVE-2019-16692
- EPSS 10.32%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CVE-2019-1000010
- EPSS 0.86%
- Veröffentlicht 04.02.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:40
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker....