CVE-2020-7988

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
04/03/2020
Last modified:
05/03/2020

Description

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpipam:phpipam:1.4:*:*:*:*:*:*:*