CVE-2022-23045

Source
https://cve.org/CVERecord?id=CVE-2022-23045
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23045.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23045
Published
2022-01-19T20:38:57Z
Modified
2026-07-15T01:49:07.389945907Z
Summary
[none]
Details

PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.

Database specific
{
    "cna_assigner": "Fluid Attacks",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23045.json"
}
References

Affected packages

Git / github.com/phpipam/phpipam

Affected ranges

Type
GIT
Repo
https://github.com/phpipam/phpipam
Events
Database specific
{
    "cpe": "cpe:2.3:a:phpipam:phpipam:1.4.4:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.4.4"
        },
        {
            "last_affected": "1.4.4"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.4.4
v1.*
v1.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23045.json"