Cross Site Scripting Flaw in phpIPAM by phpipam
CVE-2018-1000860
4.7MEDIUM
What is CVE-2018-1000860?
The phpIPAM application contains a Cross Site Scripting vulnerability due to improper handling of the phpipamredirect cookie value. When the value is manipulated, it can be exploited to execute arbitrary code in the browser of a victim accessing the login page. Exploitation requires the attacker to set or modify a cookie for the phpIPAM instance's domain, potentially chaining this attack with other vulnerabilities.
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved