CVE-2024-10727

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2024-10727 is a reflected cross-site scripting (XSS) vulnerability affecting phpipam versions 1.5.0 through 1.6.0. The issue occurs when the application fails to properly sanitize user input in HTTP requests, leading to the inclusion of this data in the immediate response. An attacker can exploit this vulnerability by injecting malicious JavaScript code, which is then executed in the user's browser. Successful exploitation could result in full compromise of the affected user.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share