PT-2025-12063 · Phpipam · Phpipam

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-10727

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpipam/phpipam versions 1.5.0 through 1.6.0
Description A reflected cross-site scripting (XSS) issue exists, arising when the application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. This allows an attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to full compromise of the user.
Recommendations For versions 1.5.0 through 1.6.0, update to a version that fixes this issue to prevent reflected cross-site scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10727

Affected Products

Phpipam