CVE-2022-23045: XSS
Published Jan 19, 2022
·Updated
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.
Affected Software
1 affected component
Phpipam Phpipam=1.4.4
Event History
Jan 19, 2022
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-23045.
2
What is the severity rating of CVE-2022-23045?
CVE-2022-23045 has a severity rating of medium (4.8).
3
Which software is affected by CVE-2022-23045?
PhpIPAM v1.4.4 is affected by CVE-2022-23045.
4
How can an authenticated admin user exploit this vulnerability?
An authenticated admin user can inject persistent JavaScript code inside the "Site title" parameter while updating the site settings in PhpIPAM v1.4.4.
5
Is there a fix available for CVE-2022-23045?
Yes, the fix for CVE-2022-23045 is available in PhpIPAM version 1.4.5.