Vulnerabilities
Vulnerable Software
Phpipam:  >> Phpipam  >> 0.9  Security Vulnerabilities
A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects the import Data set feature via a spreadsheet file upload. The affected endpoints include import-vlan-preview.php, import-subnets-preview.php, import-vrf-preview.php, import-ipaddr-preview.php, import-devtype-preview.php, import-devices-preview.php, and import-l2dom-preview.php. The vulnerability can be exploited by uploading a specially crafted spreadsheet file containing malicious JavaScript payloads, which are then executed in the context of the victim's browser. This can lead to defacement of websites, execution of malicious JavaScript code, stealing of user cookies, and unauthorized access to user accounts.
CVSS Score
3.5
EPSS Score
0.001
Published
2024-11-15
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
CVSS Score
7.5
EPSS Score
0.006
Published
2023-10-02
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
7.2
EPSS Score
0.003
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-03-07
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVSS Score
2.4
EPSS Score
0.005
Published
2023-02-04
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
CVSS Score
4.4
EPSS Score
0.001
Published
2023-02-04
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVSS Score
7.5
EPSS Score
0.64
Published
2023-02-04
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 22c797c3583001211fe7d31bccd3f1d4aeeb3bbc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-212863.
CVSS Score
2.4
EPSS Score
0.003
Published
2022-11-02
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-04-04
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-04-04


Contact Us

Shodan ® - All rights reserved