A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT destination address, where user input is not properly sanitized. This can lead to data theft, account compromise, and other malicious activities. The vulnerability is fixed in version 1.7.0.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phpipam
Phpipam phpipam |
|
CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
Vendors & Products |
Phpipam
Phpipam phpipam |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT destination address, where user input is not properly sanitized. This can lead to data theft, account compromise, and other malicious activities. The vulnerability is fixed in version 1.7.0. | |
Title | Stored Cross-site Scripting (XSS) in phpipam/phpipam | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:09:15.972Z
Updated: 2025-03-20T18:57:09.070Z
Reserved: 2024-11-01T23:25:52.660Z
Link: CVE-2024-10725

Updated: 2025-03-20T17:51:29.884Z

Status : Analyzed
Published: 2025-03-20T10:15:19.513
Modified: 2025-05-28T20:34:29.100
Link: CVE-2024-10725

No data.