Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j22-hr4w-47gj

Опубликовано: 08 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.

EPSS

Процентиль: 29%
0.00103
Низкий

3.3 Low

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 3.3
nvd
2 месяца назад

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.

CVSS3: 3.3
debian
2 месяца назад

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerabil ...

EPSS

Процентиль: 29%
0.00103
Низкий

3.3 Low

CVSS3

Дефекты

CWE-352