CVE-2019-16694: SQL Injection
Published Sep 22, 2019
·Updated
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
Affected Software
1 affected component
Phpipam Phpipam<=1.4
Event History
Sep 22, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16694?
The severity of CVE-2019-16694 is critical with a severity score of 9.8.
2
How does CVE-2019-16694 affect phpIPAM?
CVE-2019-16694 affects phpIPAM version 1.4.
3
What is the CWE of CVE-2019-16694?
The CWE of CVE-2019-16694 is CWE-89, which stands for Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').
4
How can I fix CVE-2019-16694?
To fix CVE-2019-16694, it is recommended to update phpIPAM to a version that has addressed the SQL injection vulnerability.
5
Where can I find more information about CVE-2019-16694?
More information about CVE-2019-16694 can be found at the following link: <a href="https://github.com/phpipam/phpipam/issues/2738">https://github.com/phpipam/phpipam/issues/2738</a>.