CVE-2024-10724

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*

History

28 May 2025, 20:34

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en phpipam/phpipam versión 1.5.2, específicamente en la sección de traducciones NAT de subred al editar la dirección de destino. Esta vulnerabilidad permite a un atacante ejecutar código malicioso. El problema se ha corregido en la versión 1.7.0.
First Time Phpipam phpipam
Phpipam
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*
References () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - Patch
References () https://huntr.com/bounties/0746e357-fcc7-44db-b8e7-857875c54999 - () https://huntr.com/bounties/0746e357-fcc7-44db-b8e7-857875c54999 - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-05-28 20:34


NVD link : CVE-2024-10724

Mitre link : CVE-2024-10724

CVE.ORG link : CVE-2024-10724


JSON object : View

Products Affected

phpipam

  • phpipam
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')