CVE-2024-10721: Store XSS in phpipam/phpipam
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view the affected page. The issue occurs in the circuits options page (https://demo.phpipam.net/tools/circuits/options/). An attacker can exploit this vulnerability to steal cookies, gain unauthorized access to user accounts, or redirect users to malicious websites. The vulnerability has been fixed in version 1.7.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10721?
CVE-2024-10721 has a medium severity rating due to its potential for exploitation through stored cross-site scripting.
How do I fix CVE-2024-10721?
To fix CVE-2024-10721, upgrade phpipam/phpipam to version 1.5.3 or later.
What kind of attacks can be executed due to CVE-2024-10721?
CVE-2024-10721 allows attackers to execute malicious scripts in the browsers of users who view affected pages.
Who is affected by CVE-2024-10721?
CVE-2024-10721 affects users of phpipam/phpipam version 1.5.2.
Is there a public exploit for CVE-2024-10721?
As of now, there are no publicly available exploits specifically targeting CVE-2024-10721.