A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects the import Data set feature via a spreadsheet file upload. The affected endpoints include import-vlan-preview.php, import-subnets-preview.php, import-vrf-preview.php, import-ipaddr-preview.php, import-devtype-preview.php, import-devices-preview.php, and import-l2dom-preview.php. The vulnerability can be exploited by uploading a specially crafted spreadsheet file containing malicious JavaScript payloads, which are then executed in the context of the victim's browser. This can lead to defacement of websites, execution of malicious JavaScript code, stealing of user cookies, and unauthorized access to user accounts.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 15 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phpipam
Phpipam phpipam |
|
CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
Vendors & Products |
Phpipam
Phpipam phpipam |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects the import Data set feature via a spreadsheet file upload. The affected endpoints include import-vlan-preview.php, import-subnets-preview.php, import-vrf-preview.php, import-ipaddr-preview.php, import-devtype-preview.php, import-devices-preview.php, and import-l2dom-preview.php. The vulnerability can be exploited by uploading a specially crafted spreadsheet file containing malicious JavaScript payloads, which are then executed in the context of the victim's browser. This can lead to defacement of websites, execution of malicious JavaScript code, stealing of user cookies, and unauthorized access to user accounts. | |
Title | Cross-site Scripting (XSS) in phpipam/phpipam | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-11-15T10:57:20.597Z
Updated: 2024-11-15T20:59:32.661Z
Reserved: 2022-04-04T10:41:01.205Z
Link: CVE-2022-1226
Vulnrichment
Updated: 2024-11-15T20:59:27.691Z
NVD
Status : Analyzed
Published: 2024-11-15T11:15:07.527
Modified: 2024-11-19T15:30:53.477
Link: CVE-2022-1226
Redhat
No data.