Home

Description

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.

PUBLISHED Reserved 2025-09-26 | Published 2025-12-08 | Updated 2025-12-08 | Assigner mitre

References

github.com/phpipam/phpipam

gist.github.com/amandrei/a8377d9b71c55156d22aaaf485463d15

cve.org (CVE-2025-60912)

nvd.nist.gov (CVE-2025-60912)

Download JSON