CVE-2025-60912 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the…
Low CVSS: 3.3

CVE-2025-60912

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.
Vendor
Phpipam
Product
Phpipam
CWE
CWE-352
Yayın Tarihi
2025-12-08 15:15:50
Güncelleme
2025-12-10 17:36:31
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar