PT-2024-5305 · Phpipam · Phpipam

Xjzzzxx

·

Published

2024-07-26

·

Updated

2025-04-23

·

CVE-2024-41354

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions phpipam version 1.6
Description The issue is related to Cross Site Scripting (XSS) in the phpipam application. Specifically, the "/app/admin/widgets/edit.php" endpoint is vulnerable. This vulnerability can be exploited by a remote attacker to conduct an XSS attack. The vulnerability exists due to insufficient protection of the web page structure, particularly in the "appadmingroupsedit-group.php" script.
Recommendations For phpipam version 1.6, consider disabling access to the "/app/admin/widgets/edit.php" endpoint until a patch is available. As a temporary workaround, restrict the use of the edit functionality in the widgets section to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-05933
CVE-2024-41354

Affected Products

Phpipam