CVE-2021-35438: XSS
Published Jun 23, 2021
·Updated
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
Affected Software
1 affected component
Phpipam Phpipam=1.4.3
Remediation
Patch Available
Event History
Jun 23, 2021
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-35438.
2
What software version is affected by this vulnerability?
phpIPAM version 1.4.3 is affected by this vulnerability.
3
What is the severity of CVE-2021-35438?
The severity of CVE-2021-35438 is medium, with a severity value of 6.1.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through Reflected XSS via the 'ipcalc-result.php' and 'result.php' pages of the IP calculator in phpIPAM 1.4.3.
5
Is there a fix available for this vulnerability?
At the moment, there is no known fix for this vulnerability. It is recommended to follow the official GitHub issue (https://github.com/phpipam/phpipam/issues/3351) for updates and patches.