Beveiligingsadvies

CVE-2022-23045

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-01-19 20:38:57
Laatst bijgewerkt 2024-08-03 03:28:43
Toegewezen door Fluid Attacks
CVSS-score geen score
Status PUBLISHED

Beschrijving

PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.