phpipam 1.6 vulnerable to Cross Site Scripting (XSS)
CVE-2024-41354
7.1HIGH
What is CVE-2024-41354?
phpipam version 1.6 contains a Cross Site Scripting (XSS) vulnerability located at /app/admin/widgets/edit.php. An attacker can exploit this flaw to inject malicious scripts into web pages viewed by users, potentially leading to data theft, session hijacking, or other malicious actions. It is crucial for users of phpipam 1.6 to apply necessary updates or implement security measures to safeguard against this threat.
