Home

Description

Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.

PUBLISHED Reserved 2025-09-26 | Published 2025-12-09 | Updated 2025-12-11 | Assigner mitre

References

phpipam.com

glitch0ne.com/...ility-in-request-ip-form-in-phpipam-v1-7-3/

cve.org (CVE-2025-61078)

nvd.nist.gov (CVE-2025-61078)

Download JSON