CVE-2024-41357: XSS
Published Jul 26, 2024
·Updated
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
Affected Software
2 affected components
Phpipam Phpipam
Phpipam Phpipam=1.6
Event History
Jul 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 2, 2025
Exploit Published
12:00 AM
Known Exploited
07:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-41357?
CVE-2024-41357 has been classified as a moderate severity Cross Site Scripting vulnerability.
2
How do I fix CVE-2024-41357?
To mitigate CVE-2024-41357, it is recommended to patch phpIPAM to the latest version that addresses the XSS vulnerability.
3
What could an attacker do with CVE-2024-41357?
An attacker exploiting CVE-2024-41357 could inject malicious scripts into the application, potentially compromising user data.
4
Is CVE-2024-41357 present in all phpIPAM versions?
CVE-2024-41357 specifically affects phpIPAM version 1.6, so other versions may not be impacted.
5
How was CVE-2024-41357 discovered?
CVE-2024-41357 was discovered through community reporting on the phpIPAM GitHub issues page.