Cross-Site Request Forgery Vulnerability in phpIPAM by phpIPAM
CVE-2025-60912

3.3LOW

Key Information:

Vendor

phpIPAM

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-60912?

A Cross-Site Request Forgery (CSRF) vulnerability exists in phpIPAM v1.7.3 affecting the database export feature. This flaw occurs within the generate-mysql.php function at the /app/admin/import-export/ endpoint. Remote attackers can exploit this vulnerability by sending specially crafted HTTP GET requests to trigger unauthorized database dump downloads when an administrator is logged in. This potential risk emphasizes the need for improved security measures to protect against unauthorized access and data leakage.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.