CVE-2024-10723

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact of this vulnerability includes the potential theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites. The issue has been fixed in version 1.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*

History

28 May 2025, 20:34

Type Values Removed Values Added
First Time Phpipam
Phpipam phpipam
CVSS v2 : unknown
v3 : 3.5
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*
References () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - () https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731 - Patch
References () https://huntr.com/bounties/9af99057-e4f6-4d07-b3bb-3213b977801d - () https://huntr.com/bounties/9af99057-e4f6-4d07-b3bb-3213b977801d - Exploit, Third Party Advisory
Summary
  • (es) Se descubrió una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en phpipam/phpipam versión 1.5.2. Esta vulnerabilidad permite a un atacante inyectar scripts maliciosos en el campo de dirección de destino de la herramienta NAT, que pueden ejecutarse cuando un usuario interactúa con dicho campo. El impacto de esta vulnerabilidad incluye el posible robo de cookies de usuario, acceso no autorizado a cuentas de usuario y redirección a sitios web maliciosos. El problema se ha corregido en la versión 1.7.0.

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-05-28 20:34


NVD link : CVE-2024-10723

Mitre link : CVE-2024-10723

CVE.ORG link : CVE-2024-10723


JSON object : View

Products Affected

phpipam

  • phpipam
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')