CVE-2019-16693: SQL Injection
Published Sep 22, 2019
·Updated
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
Affected Software
1 affected component
Phpipam Phpipam<=1.4
Event History
Sep 22, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Dec 3, 2025
Exploit Published
12:00 AM
Known Exploited
11:13 AM
Frequently Asked Questions
1
What is the vulnerability ID of phpIPAM?
The vulnerability ID of phpIPAM is CVE-2019-16693.
2
What is the severity of CVE-2019-16693?
The severity of CVE-2019-16693 is critical with a severity value of 9.8.
3
What is the affected software version of CVE-2019-16693?
The affected software version of CVE-2019-16693 is phpIPAM 1.4.
4
How does CVE-2019-16693 exploit SQL injection?
CVE-2019-16693 exploits SQL injection by using the app/admin/custom-fields/order.php table parameter when action=add is used.
5
Is there a fix available for CVE-2019-16693?
Yes, a fix is available for CVE-2019-16693. It is recommended to update phpIPAM to a version that is not affected by the vulnerability.