A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT destination address, where user input is not properly sanitized. This can lead to data theft, account compromise, and other malicious activities. The vulnerability is fixed in version 1.7.0.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 28 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Phpipam
         Phpipam phpipam  | 
|
| CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Phpipam
         Phpipam phpipam  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT destination address, where user input is not properly sanitized. This can lead to data theft, account compromise, and other malicious activities. The vulnerability is fixed in version 1.7.0. | |
| Title | Stored Cross-site Scripting (XSS) in phpipam/phpipam | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_0
         
  | 
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:57:09.070Z
Reserved: 2024-11-01T23:25:52.660Z
Link: CVE-2024-10725
Updated: 2025-03-20T17:51:29.884Z
Status : Analyzed
Published: 2025-03-20T10:15:19.513
Modified: 2025-05-28T20:34:29.100
Link: CVE-2024-10725
No data.