CVE-2024-10720
CVSS 3.0 Score 8.2 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 79
Summary
CVE-2024-10720 is a stored cross-site scripting (XSS) vulnerability affecting phpipam/phpipam version 1.5.2. In the 'Device Management' section under 'Administration', an attacker can inject malicious scripts into the 'Name' and 'Description' fields when adding a new device type. This can result in data theft, account compromise, malware distribution, website defacement, and phishing attacks. The vulnerability has been addressed in version 1.7.0. Users are strongly urged to upgrade to this version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.