Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-1211. PoCs published by CodeSecLab.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in phpIPAM 1.5.1 via the `fieldSize` parameter in a POST request to `/app/admin/custom-fields/edit-result.php`. The payload uses a time-based SQLi technique (`SELECT SLEEP(10)`) to confirm vulnerability, requiring valid session and CSRF tokens.
Description
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in phpIPAM 1.5.1 via the `fieldSize` parameter in a POST request to `/app/admin/custom-fields/edit-result.php`. The payload uses a time-based SQLi technique (`SELECT SLEEP(10)`) to confirm vulnerability, requiring valid session and CSRF tokens.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H