Filtered by vendor Phpipam
Subscribe
Search
Total
2 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-23046 | 1 Phpipam | 1 Phpipam | 2022-02-11 | 6.5 MEDIUM | 7.2 HIGH |
| PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | |||||
| CVE-2020-7988 | 1 Phpipam | 1 Phpipam | 2020-03-05 | 6.8 MEDIUM | 8.8 HIGH |
| An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens. | |||||
