Low severity3.3OSV Advisory· Published Dec 8, 2025· Updated Jun 17, 2026
CVE-2025-60912
CVE-2025-60912
Description
phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- gist.github.com/amandrei/a8377d9b71c55156d22aaaf485463d15nvdThird Party Advisory
News mentions
0No linked articles in our index yet.