CVE-2023-0677: Cross-site Scripting (XSS) - Reflected in phpipam/phpipam
Published Feb 4, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
Affected Software
1 affected component
Phpipam Phpipam<1.5.1
Remediation
Event History
Feb 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0677?
The severity of CVE-2023-0677 is medium.
2
How does CVE-2023-0677 affect phpipam/phpipam?
CVE-2023-0677 affects phpipam/phpipam versions prior to v1.5.1 by allowing cross-site scripting (XSS) attacks.
3
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
4
How can I fix CVE-2023-0677 in phpipam/phpipam?
To fix CVE-2023-0677, upgrade to phpipam/phpipam version 1.5.1 or higher.
5
Where can I find more information about CVE-2023-0677?
You can find more information about CVE-2023-0677 at the following references: [Link 1](https://github.com/phpipam/phpipam/commit/8fbf87e19a6098972abc7521554db5757c3edd89) and [Link 2](https://huntr.dev/bounties/d280ae81-a1c9-4a50-9aa4-f98f1f9fd2c0).