CVE-2018-1000869

CRITICAL

phpIPAM <1.3.2 - SQL Injection

Title source: llm
STIX 2.1

Description

phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This vulnerability appears to have been fixed in 1.4.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/phpipam/phpipam/issues/2344

Scores

CVSS v3 9.8
EPSS 0.0028
EPSS Percentile 51.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
phpipam/phpipam 1.3.2
Published Dec 20, 2018
Tracked Since Feb 18, 2026