CVE-2019-1000010

MEDIUM

phpIPAM <1.3.2 - XSS

Title source: llm
STIX 2.1

Description

phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker. This vulnerability appears to have been fixed in 1.4.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/phpipam/phpipam/issues/2327

Scores

CVSS v3 6.1
EPSS 0.0022
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
phpipam/phpipam < 1.3.2
Published Feb 04, 2019
Tracked Since Feb 18, 2026