Vulnerabilities
Vulnerable Software
Phpipam:  >> Phpipam  >> 1.5.1  Security Vulnerabilities
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
CVSS Score
7.5
EPSS Score
0.006
Published
2023-10-02
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.
CVSS Score
2.7
EPSS Score
0.002
Published
2023-09-14
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
7.2
EPSS Score
0.001
Published
2023-03-07
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-03-07


Contact Us

Shodan ® - All rights reserved