A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/ctflearner/Vulnerability/blob/main/PHPIPAM/Open_Redirect.md | Exploit Vendor Advisory | 
| https://vuldb.com/?ctiid.239732 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.239732 | Permissions Required Third Party Advisory | 
| https://github.com/ctflearner/Vulnerability/blob/main/PHPIPAM/Open_Redirect.md | Exploit Vendor Advisory | 
| https://vuldb.com/?ctiid.239732 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.239732 | Permissions Required Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 08:36
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : 3.3 v3 : 2.7 | 
| References | () https://github.com/ctflearner/Vulnerability/blob/main/PHPIPAM/Open_Redirect.md - Exploit, Vendor Advisory | |
| References | () https://vuldb.com/?ctiid.239732 - Permissions Required, Third Party Advisory | |
| References | () https://vuldb.com/?id.239732 - Permissions Required, Third Party Advisory | 
29 Feb 2024, 01:41
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-09-14 20:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-4965
Mitre link : CVE-2023-4965
CVE.ORG link : CVE-2023-4965
JSON object : View
Products Affected
                phpipam
- phpipam
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
