CVE-2023-4965: phpipam Header redirect
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4965?
The severity of CVE-2023-4965 is medium with a CVSS score of 4.8.
What is the affected software for CVE-2023-4965?
Phpipam version 1.5.1 is the affected software for CVE-2023-4965.
What is the vulnerability in phpipam 1.5.1?
The vulnerability in phpipam 1.5.1 is an open redirect issue caused by the manipulation of the argument X-Forwarded-Host.
Is the vulnerability in phpipam 1.5.1 exploitable remotely?
Yes, the vulnerability in phpipam 1.5.1 can be exploited remotely.
How can I fix the open redirect vulnerability in phpipam 1.5.1?
To fix the open redirect vulnerability in phpipam 1.5.1, update to a patched version of the software when available.