PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.
References
Link Resource
https://fluidattacks.com/advisories/osbourne/ Exploit Third Party Advisory
https://github.com/phpipam/phpipam/releases/tag/v1.4.5 Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2022-01-19T20:38:57

Updated: 2022-01-19T20:38:57

Reserved: 2022-01-10T00:00:00


Link: CVE-2022-23045

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-19T21:15:09.077

Modified: 2022-01-25T15:32:30.817


Link: CVE-2022-23045

JSON object: View

cve-icon Redhat Information

No data.

CWE