CVE-2018-1000870: XSS
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in admin-panel and gets exploited.. This vulnerability appears to have been fixed in 1.4.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this PHPipam vulnerability?
The vulnerability ID for this PHPipam vulnerability is CVE-2018-1000870.
What is the name of the software affected by this vulnerability?
The software affected by this vulnerability is PHPipam.
What is the severity rating of CVE-2018-1000870?
The severity rating of CVE-2018-1000870 is medium, with a severity value of 5.4.
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-79.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by changing the theme parameter in user settings, which can result in executing code in the victim's browser.