CVE-2019-16692: SQL Injection
Published Sep 22, 2019
·Updated
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
Affected Software
1 affected component
Phpipam Phpipam<=1.4
Event History
Sep 22, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16692?
The severity of CVE-2019-16692 is critical.
2
How does CVE-2019-16692 affect phpIPAM?
CVE-2019-16692 affects phpIPAM version 1.4.
3
What is the vulnerability in phpIPAM version 1.4?
The vulnerability in phpIPAM version 1.4 is SQL injection.
4
How can SQL injection be exploited in phpIPAM version 1.4?
SQL injection can be exploited in phpIPAM version 1.4 through the table parameter in app/admin/custom-fields/filter-result.php when the action=add is used.
5
Are there any references for CVE-2019-16692?
Yes, you can find references for CVE-2019-16692 at the following links: [Link1](http://packetstormsecurity.com/files/154651/phpIPAM-1.4-SQL-Injection.html), [Link2](https://github.com/phpipam/phpipam/issues/2738).