← Back

CVE-2024-10720

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' section under 'Administration' where an attacker can inject malicious scripts into the 'Name' and 'Description' fields when adding a new device type. This can lead to data theft, account compromise, distribution of malware, website defacement, and phishing attacks. The issue is fixed in version 1.7.0.

Affected (1)

Products: Phpipam: Phpipam
1 product
Phpipam
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.7.0

References (2)

Timeline

No history available yet.