CVE-2024-10723
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact of this vulnerability includes the potential theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites. The issue has been fixed in version 1.7.0.
- Affected products
- Phpipam
- Phpipam
- < 1.7.0
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.3% (25th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2025-03-20
CVE-2024-10723 at NVD
No indexed exploits for CVE-2024-10723 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-10723 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.