RULE(RULE ID:336610)

Rule General Information
Release Date: 2022-05-24
Rule Name: PhpIPAM v1.4.4 Authenticated SQL Injection Vulnerability (CVE-2022-23046)
Severity:
CVE ID:
Rule Protection Details
Description: PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/165683/PHPIPAM-1.4.4-SQL-Injection.html
https://fluidattacks.com/advisories/mercury/
https://github.com/phpipam/phpipam/releases/tag/v1.4.5
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://github.com/phpipam/phpipam/releases/tag/v1.4.5