A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. This allows an attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to full compromise of the user.
References
Configurations
History
01 Apr 2025, 20:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
First Time |
Phpipam phpipam
Phpipam |
|
References | () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - Patch | |
References | () https://huntr.com/bounties/259eed22-4d6f-4229-92e5-04674f302d5d - Exploit | |
CPE | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
Summary |
|
20 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/259eed22-4d6f-4229-92e5-04674f302d5d - |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-04-01 20:35
NVD link : CVE-2024-10727
Mitre link : CVE-2024-10727
CVE.ORG link : CVE-2024-10727
JSON object : View
Products Affected
phpipam
- phpipam
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')