CVE-2023-0676
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into web pages viewed by users of the phpipam application, potentially stealing sensitive information like session cookies. It occurs when users click on specially crafted links, and it affects versions prior to 1.5.1.
Technical Description
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 4, 2023
about 3 years ago
Last Modified
Feb 13, 2026
7 days ago
Vendor
phpipam
Product
phpipam
Related Vulnerabilities
This vulnerability allows an attacker to manipulate the database of phpipam, potentially gaining access to sensitive information or altering data. It affects versions prior to 1.5.2 and requires the attacker to have the ability to send specially crafted requests to the application.
This vulnerability allows an attacker to inject malicious scripts into the IP calculator feature of phpIPAM, which can then execute in the browser of anyone who visits the affected pages. To exploit this, the attacker needs to trick users into clicking on a specially crafted link that leads to the vulnerable pages.