CVE-2024-10722: Stored Cross-site Scripting (XSS) in phpipam/phpipam
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can lead to data theft, account compromise, distribution of malware, website defacement, content manipulation, and phishing attacks. The issue is fixed in version 1.7.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10722?
CVE-2024-10722 is classified as a stored cross-site scripting (XSS) vulnerability affecting phpipam version 1.5.2.
How do I fix CVE-2024-10722?
To fix CVE-2024-10722, upgrade to the latest version of phpipam where this vulnerability has been addressed.
What impact does CVE-2024-10722 have on affected systems?
CVE-2024-10722 may allow attackers to inject malicious scripts that can lead to data theft and account compromise.
Which version of phpipam is affected by CVE-2024-10722?
CVE-2024-10722 affects phpipam version 1.5.2.
Where can I find more information about CVE-2024-10722?
More information about CVE-2024-10722 can be found in official vulnerability databases such as MITRE.