Vulnerabilities
Vulnerable Software
Phpipam:  >> Phpipam  >> 1.7.3  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-12-09
phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.
CVSS Score
3.3
EPSS Score
0.001
Published
2025-12-08
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.
CVSS Score
5.4
EPSS Score
0.0
Published
2025-03-31


Contact Us

Shodan ® - All rights reserved