CVE-2023-1211

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to manipulate the database of phpipam, potentially gaining access to sensitive information or altering data. It affects versions prior to 1.5.2 and requires the attacker to have the ability to send specially crafted requests to the application.

Technical Description

SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References