Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2023-0676

Disclosure Date: February 04, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
Attacker Value
Unknown

CVE-2022-3845

Disclosure Date: November 02, 2022 (last updated November 08, 2023)
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 22c797c3583001211fe7d31bccd3f1d4aeeb3bbc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-212863.
Attacker Value
Unknown

CVE-2022-41443

Disclosure Date: October 03, 2022 (last updated October 08, 2023)
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
Attacker Value
Unknown

CVE-2022-1225

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
Attacker Value
Unknown

CVE-2022-1224

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Attacker Value
Unknown

CVE-2022-1223

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Attacker Value
Unknown

CVE-2021-46426

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
Attacker Value
Unknown

CVE-2022-23046

Disclosure Date: January 19, 2022 (last updated October 07, 2023)
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Attacker Value
Unknown

CVE-2022-23045

Disclosure Date: January 19, 2022 (last updated October 07, 2023)
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.
Attacker Value
Unknown

CVE-2021-35438

Disclosure Date: June 23, 2021 (last updated February 22, 2025)
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.