PT-2025-12060 · Phpipam · Phpipam
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-10723
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
phpipam/phpipam version 1.5.2
Description
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam. This issue allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact includes the potential theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites.
Recommendations
For version 1.5.2, update to version 1.7.0 to resolve the issue. As a temporary workaround, consider restricting access to the NAT tool to minimize the risk of exploitation. Avoid using the destination address field in the NAT tool until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpipam