CVE-2024-10724 - CERT CVE
ID CVE-2024-10724
Sažetak A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.
Reference
CVSS
Base: 3.5
Impact: 1.4
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Zadnje važnije ažuriranje 20-03-2025 - 10:15
Objavljeno 20-03-2025 - 10:15