PoC Index

CVE-2022-23045

MEDIUM 4.8EPSS 0.6%

PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.62% chance of exploitation in the next 30 days, 47th percentile
Published
2022-01-19
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related