phpipam/phpipam
cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*
- 1.5.2
A stored cross-site scripting vulnerability has been identified in phpipam/phpipam version 1.5.2. This issue allows attackers to inject malicious scripts into the destination address field of the NAT tool. These scripts can be executed when a user interacts with the field. The vulnerability could lead to the theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites. This issue has been resolved in version 1.7.0.
Exploitation of this vulnerability could result in stored cross-site scripting, allowing injected scripts to be executed in the context of the user.
Users can upgrade to phpipam version 1.7.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.