CVE-2018-1000869: Phpipam
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This vulnerability appears to have been fixed in 1.4.
Affected products
- Phpipam Phpipam: version 1.3.2 only
Published 2018-12-20. Last modified 2026-06-17.