PT-2026-76800 · Phpipam · Phpipam
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpIPAM versions prior to 1.8.2
Description
An issue exists where the software fails to verify if a requested IP address belongs to the subnet for which a temporary share token was issued. In the endpoints 'app/temp share/index.php' and 'app/temp share/address.php', when the share type is set to 'subnets', the
subnetId parameter is used as a database primary key to retrieve an address without validating its membership in the authorized subnet. An unauthenticated user with a valid, non-expired temporary share URL can enumerate the subnetId parameter to access all IP address records across all sections and subnets, potentially exposing hostnames, DNS names, MAC addresses, owner/contact fields, and notes that may contain credentials or configuration details.Recommendations
Update phpIPAM to version 1.8.2 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpipam