CVE-2023-24657: XSS
Published Mar 8, 2023
·Updated
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
Affected Software
1 affected component
Phpipam Phpipam=1.6
Remediation
Patch Available
Event History
Mar 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 11, 2025
Exploit Published
12:00 AM
Known Exploited
05:48 AM
Frequently Asked Questions
1
What is CVE-2023-24657?
CVE-2023-24657 is a reflected cross-site scripting (XSS) vulnerability in phpipam v1.6.
2
How severe is CVE-2023-24657?
CVE-2023-24657 has a severity level of medium (6.1).
3
How does CVE-2023-24657 affect phpipam v1.6?
CVE-2023-24657 affects phpipam v1.6 through the closeClass parameter in the /subnet-masks/popup.php page.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-24657?
CVE-2023-24657 is associated with CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
Is there a reference link for CVE-2023-24657?
Yes, you can find the reference link for CVE-2023-24657 at https://github.com/phpipam/phpipam/issues/3738.