CVE-2024-10724

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/03/2025
Last modified:
28/05/2025

Description

A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* 1.7.0 (excluding)