| BDSA-2025-50059 |
|
Low |
Dec 09, 2025 |
phpIPAM is vulnerable to cross-site request forgery (CSRF) due to missing CSRF token validation in the `generate-mysql.php` functionality within the `/
more...
phpIPAM is vulnerable to cross-site request forgery (CSRF) due to missing CSRF token validation in the `generate-mysql.php` functionality within the `/app/admin/import-export/` endpoint. This could allow an attacker to trigger unauthorized database exports, potentially leading to denial-of-service (DoS) or indirect exposure of sensitive information.
less...
|
|
| BDSA-2024-4773 |
|
High |
Jul 29, 2024 |
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
**Note: CVE details have been utilized in generating this
more...
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2024-4772 |
|
High |
Jul 29, 2024 |
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
**Note: CVE details have been utilized in generating this advi
more...
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2024-4770 |
|
High |
Jul 29, 2024 |
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
**Note: CVE details have been utilized in
more...
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2024-4765 |
|
High |
Jul 29, 2024 |
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
**Note: CVE details have been utilized in generating
more...
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|
| BDSA-2024-4759 |
|
High |
Jul 29, 2024 |
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
**Note: CVE details have been utilized in generating this
more...
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by BlackDuck CyRC.**
less...
|
|