CVE-2024-41357: phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

7.1 CVSS

Description

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

Classification

CVE ID: CVE-2024-41357

CVSS Base Severity: HIGH

CVSS Base Score: 7.1

Affected Products

Vendor: n/a

Product: n/a

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 3.49% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: poc

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-41357
https://github.com/phpipam/phpipam/issues/4149
https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2024-41357.md

Timeline