Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rodtvs

#44783of 53,619
5.8Total CVSS
Vulnerabilities · 1
PT-2026-25562
5.8
2026-03-15
Undefined · Undefined · CVE-2026-4189
**Name of the Vulnerable Software and Affected Versions** phpipam versions up to 1.7.4 **Description** A weakness exists in phpipam that could allow for SQL injection. The issue is located in an unknown function within the `app/admin/sections/edit-result.php` file of the Section Handler component. Manipulating the `subnetOrdering` argument can trigger the SQL injection. The attack can be launched remotely, and an exploit is publicly available. The vendor was contacted regarding this issue but did not respond. **Recommendations** Versions prior to 1.7.4 should be updated.