AI description
Automated description summarized from trusted sources.
CVE-2022-23046 is a SQL injection vulnerability found in PhpIPAM version 1.4.4. This flaw specifically affects the BGP mapping search functionality within the application's administrative interface. The vulnerability arises because the application fails to properly sanitize user-supplied input in the "subnet" parameter. An authenticated administrator can exploit this by injecting malicious SQL commands when searching for subnets, allowing for direct manipulation of database queries. This could potentially lead to unauthorized access, modification, or complete compromise of the database.
- Description
- PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
- Source
- help@fluidattacks.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.2
- Impact score
- 5.9
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 6.4
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:P/A:P
- nvd@nist.gov
- CWE-89
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:phpipam:phpipam:1.4.4:*:*:*:*:*:*:*",
"matchCriteriaId": "8740D50B-34B1-44D3-B6CF-93047F04D587",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]