CVE-2024-10721 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scr…
Medium CVSS: 5.4

CVE-2024-10721

A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view the affected page. The issue occurs in the circuits options page (https://demo.phpipam.net/tools/circuits/options/). An attacker can exploit this vulnerability to steal cookies, gain unauthorized access to user accounts, or redirect users to malicious websites. The vulnerability has been fixed in version 1.7.0.
Vendor
Phpipam
Product
Phpipam
CWE
CWE-79
Yayın Tarihi
2025-03-20 10:15:19
Güncelleme
2025-04-01 20:35:45
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar