PT-2025-12056 · Phpipam · Phpipam
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-10719
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
phpipam versions 1.5.2 through 1.6.x
Description
A stored cross-site scripting (XSS) issue exists, specifically in the circuits options functionality. This allows an attacker to inject malicious scripts via the
option parameter in the POST request to "/phpipam/app/admin/circuits/edit-options-submit.php". The injected script can be executed in the context of the user's browser, leading to potential cookie theft and end-user file disclosure.Recommendations
For versions prior to 1.7.0, update to version 1.7.0 to resolve the issue.
As a temporary workaround, consider restricting access to the "/phpipam/app/admin/circuits/edit-options-submit.php" endpoint until the issue is resolved.
Avoid using the
option parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpipam