Vulnerabilities (CVE)

Filtered by vendor Phpipam Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23046 1 Phpipam 1 Phpipam 2022-02-11 6.5 MEDIUM 7.2 HIGH
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
CVE-2020-7988 1 Phpipam 1 Phpipam 2020-03-05 6.8 MEDIUM 8.8 HIGH
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.