CVE-2022-23046

HIGH LAB

Phpipam - SQL Injection

Title source: rule

Description

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

Exploits (6)

exploitdb WORKING POC
by Rodolfo Tavares · pythonwebappsphp
https://www.exploit-db.com/exploits/50684
github FAILED 4 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/cves_exploits/tree/main/CVE-2022-23046
nomisec WORKING POC 4 stars
by dnr6419 · poc
https://github.com/dnr6419/CVE-2022-23046
nomisec WORKING POC 1 stars
by bernauers · poc
https://github.com/bernauers/CVE-2022-23046
nomisec WORKING POC 1 stars
by jcarabantes · poc
https://github.com/jcarabantes/CVE-2022-23046
nomisec WORKING POC
by hadrian3689 · poc
https://github.com/hadrian3689/phpipam_1.4.4

Scores

CVSS v3 7.2
EPSS 0.4898
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull phpipam/phpipam-www:v1.4.3
docker pull phpipam/phpipam-cron:latest
+2 more repos

Details

CWE
CWE-89
Status published
Products (1)
phpipam/phpipam 1.4.4
Published Jan 19, 2022
Tracked Since Feb 18, 2026