A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can lead to data theft, account compromise, distribution of malware, website defacement, content manipulation, and phishing attacks. The issue is fixed in version 1.7.0.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 28 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Phpipam
         Phpipam phpipam  | 
|
| CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Phpipam
         Phpipam phpipam  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can lead to data theft, account compromise, distribution of malware, website defacement, content manipulation, and phishing attacks. The issue is fixed in version 1.7.0. | |
| Title | Stored Cross-site Scripting (XSS) in phpipam/phpipam | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_0
         
  | 
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:20:56.040Z
Reserved: 2024-11-01T23:20:38.488Z
Link: CVE-2024-10722
Updated: 2025-03-20T17:48:33.362Z
Status : Analyzed
Published: 2025-03-20T10:15:19.140
Modified: 2025-05-28T20:35:42.690
Link: CVE-2024-10722
No data.