|
|||
Rule General Information |
---|
Release Date: | 2022-05-24 | |
Rule Name: | PhpIPAM v1.4.4 Authenticated SQL Injection Vulnerability (CVE-2022-23046) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | |
Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Linux, Others | |
Reference: | http://packetstormsecurity.com/files/165683/PHPIPAM-1.4.4-SQL-Injection.html https://fluidattacks.com/advisories/mercury/ https://github.com/phpipam/phpipam/releases/tag/v1.4.5 |
|
Solutions |
---|
The vendor has released upgrade patches to fix vulnerabilities, please visit: https://github.com/phpipam/phpipam/releases/tag/v1.4.5 |