CVE-2022-23046: SQL Injection
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23046?
CVE-2022-23046 is a vulnerability in PhpIPAM v1.4.4 that allows an authenticated admin user to inject SQL sentences in the subnet parameter while searching a subnet.
What is the severity of CVE-2022-23046?
The severity of CVE-2022-23046 is high, with a severity value of 7.2 (out of 10).
How does CVE-2022-23046 affect PhpIPAM?
CVE-2022-23046 affects PhpIPAM version 1.4.4.
How can I fix CVE-2022-23046 in PhpIPAM?
To fix CVE-2022-23046 in PhpIPAM, upgrade to version 1.4.5 or later.
Is there any reference for CVE-2022-23046?
Yes, you can find references for CVE-2022-23046 at the following URLs: http://packetstormsecurity.com/files/165683/PHPIPAM-1.4.4-SQL-Injection.html, https://fluidattacks.com/advisories/mercury/, https://github.com/phpipam/phpipam/releases/tag/v1.4.5.