CVE-2018-1000870
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in admin-panel and gets exploited.. This vulnerability appears to have been fixed in 1.4.
- Phpipam
- ≤ 1.3.2
- Fix
- Available
- CVSS 3.0
- 5.4 MEDIUM
- EPSS
- 0.9% (58th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2018-12-20
CVE-2018-1000870 at NVD
No indexed exploits for CVE-2018-1000870 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-1000870 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.