A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view the affected page. The issue occurs in the circuits options page (https://demo.phpipam.net/tools/circuits/options/). An attacker can exploit this vulnerability to steal cookies, gain unauthorized access to user accounts, or redirect users to malicious websites. The vulnerability has been fixed in version 1.7.0.
References
Configurations
History
01 Apr 2025, 20:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
Phpipam phpipam
Phpipam |
|
References | () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - Patch | |
References | () https://huntr.com/bounties/a440a003-84c9-47b5-bfbd-675564abe3d8 - Exploit | |
CPE | cpe:2.3:a:phpipam:phpipam:1.5.2:*:*:*:*:*:*:* | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
20 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/a440a003-84c9-47b5-bfbd-675564abe3d8 - |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-04-01 20:35
NVD link : CVE-2024-10721
Mitre link : CVE-2024-10721
CVE.ORG link : CVE-2024-10721
JSON object : View
Products Affected
phpipam
- phpipam
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')