Medium severity5.4NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-10719
CVE-2024-10719
Description
A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerability allows an attacker to inject malicious scripts via the 'option' parameter in the POST request to /phpipam/app/admin/circuits/edit-options-submit.php. The injected script can be executed in the context of the user's browser, leading to potential cookie theft and end-user file disclosure. The issue is fixed in version 1.7.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731nvdPatch
- huntr.com/bounties/56aba8cb-4da1-44b4-8c4d-c5ba00ea3670nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.