PT-2026-80888 · Phpipam · Phpipam
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpIPAM versions prior to 1.8.2
Description
An authentication bypass exists in the REST API due to an insecure object cache keying mechanism. The cache uses only the lookup value as a key and fails to include the searched column. This allows an entry created during an
app id lookup to be used for a subsequent app code lookup. Consequently, unauthenticated attackers can use a numeric database row identifier as an API token to read, write, and delete all IP address management records.Recommendations
Update to version 1.8.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpipam