PT-2025-12060 · Phpipam · Phpipam

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-10723

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpipam/phpipam version 1.5.2
Description A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam. This issue allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact includes the potential theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites.
Recommendations For version 1.5.2, update to version 1.7.0 to resolve the issue. As a temporary workaround, consider restricting access to the NAT tool to minimize the risk of exploitation. Avoid using the destination address field in the NAT tool until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10723

Affected Products

Phpipam