Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000870

Опубликовано: 20 дек. 2018
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in admin-panel and gets exploited.. This vulnerability appears to have been fixed in 1.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*
Версия до 1.3.2 (включая)

EPSS

Процентиль: 56%
0.00344
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
debian
около 7 лет назад

PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in / ...

CVSS3: 5.4
github
больше 3 лет назад

PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in admin-panel and gets exploited.. This vulnerability appears to have been fixed in 1.4.

EPSS

Процентиль: 56%
0.00344
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79