PT-2025-12056 · Phpipam · Phpipam

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-10719

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpipam versions 1.5.2 through 1.6.x
Description A stored cross-site scripting (XSS) issue exists, specifically in the circuits options functionality. This allows an attacker to inject malicious scripts via the option parameter in the POST request to "/phpipam/app/admin/circuits/edit-options-submit.php". The injected script can be executed in the context of the user's browser, leading to potential cookie theft and end-user file disclosure.
Recommendations For versions prior to 1.7.0, update to version 1.7.0 to resolve the issue. As a temporary workaround, consider restricting access to the "/phpipam/app/admin/circuits/edit-options-submit.php" endpoint until the issue is resolved. Avoid using the option parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10719

Affected Products

Phpipam