CVE-2019-16696: SQL Injection
Published Sep 22, 2019
·Updated
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
Affected Software
1 affected component
Phpipam Phpipam<=1.4
Event History
Sep 22, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-16696.
2
What is the severity of CVE-2019-16696?
CVE-2019-16696 is considered to be a critical vulnerability with a severity rating of 9.8.
3
What is the affected software?
The affected software is phpIPAM version 1.4.
4
How does CVE-2019-16696 occur?
CVE-2019-16696 occurs due to SQL injection vulnerability in the app/admin/custom-fields/edit.php file when the action=add parameter is used with the table parameter.
5
Is there a fix available for CVE-2019-16696?
Yes, a fix for CVE-2019-16696 is available. It is recommended to update to a patched version of phpIPAM.