CVE-2024-10727
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 79
Summary
CVE-2024-10727 is a reflected cross-site scripting (XSS) vulnerability affecting phpipam versions 1.5.0 through 1.6.0. The issue occurs when the application fails to properly sanitize user input in HTTP requests, leading to the inclusion of this data in the immediate response. An attacker can exploit this vulnerability by injecting malicious JavaScript code, which is then executed in the user's browser. Successful exploitation could result in full compromise of the affected user.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- phpIPAM
Affected Vendors
- Phpipam