A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0. | |
Title | Stored XSS in IPV6 Section in phpipam/phpipam | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:09:30.561Z
Updated: 2025-03-20T18:38:13.642Z
Reserved: 2024-11-01T23:24:14.738Z
Link: CVE-2024-10724

Updated: 2025-03-20T17:50:48.659Z

Status : Received
Published: 2025-03-20T10:15:19.390
Modified: 2025-03-20T10:15:19.390
Link: CVE-2024-10724

No data.