A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.
References
Link | Resource |
---|---|
https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 | Patch |
https://huntr.com/bounties/0746e357-fcc7-44db-b8e7-857875c54999 | Exploit Third Party Advisory |
Configurations
History
28 May 2025, 20:34
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Phpipam phpipam
Phpipam |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CPE | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
References | () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - Patch | |
References | () https://huntr.com/bounties/0746e357-fcc7-44db-b8e7-857875c54999 - Exploit, Third Party Advisory |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-05-28 20:34
NVD link : CVE-2024-10724
Mitre link : CVE-2024-10724
CVE.ORG link : CVE-2024-10724
JSON object : View
Products Affected
phpipam
- phpipam
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')