CVE-2024-41355: XSS
Published Jul 26, 2024
·Updated
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
Affected Software
2 affected components
Phpipam Phpipam
Phpipam Phpipam=1.6
Event History
Jul 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-41355?
The severity of CVE-2024-41355 is classified as high due to its potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2024-41355?
To fix CVE-2024-41355, ensure that you update phpIPAM to the latest version that addresses this XSS vulnerability.
3
What are the consequences of CVE-2024-41355 exploitation?
Exploitation of CVE-2024-41355 can lead to unauthorized access to user data and session hijacking through XSS attacks.
4
Which version of phpIPAM is affected by CVE-2024-41355?
CVE-2024-41355 affects phpIPAM version 1.6.
5
Where can I find more information about CVE-2024-41355?
More information about CVE-2024-41355 can be found in the official phpIPAM GitHub repository issues.