CVE-2019-16694

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
22/09/2019
Last modified:
23/09/2019

Description

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* 1.4 (including)


References to Advisories, Solutions, and Tools