7.2
CVSSv3

CVE-2022-23046

Published: 19/01/2022 Updated: 11/02/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpipam phpipam 1.4.4

Exploits

PHPIPAM version 144 suffers from an authenticated remote SQL injection vulnerability ...

Github Repositories

Tinker Script for CVE-2022-23046

CVE-2022-23046 PHPIPAM 144 - SQLi (Authenticated) Orignal Exploit can be found here Original Exploit Author: Rodolfo "Inc0gbyt3" Tavares Tinker Script for CVE-2022-23046 I was having trouble getting the orginal script to run Went ahead and tinkered with it for my use case Used while completeing the THM room Ollie

CVE-2022-23046 The original discovery and manual PoC is from Fluidattacks: PhpIPAM v144 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-searchphp This PoC executes some easy SQLi to fetch info like: Basic Server Info SMTP Settings Other authentication method like

CVE-2022-23046 phpIPAM 1.4.4

CVE-2022-23046 phpIPAM 144 - SQL Injection phpIPAM v144 allows an authenticated admin user to inject SQL sentences in the subnet parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-searchphp This project currently prints out database information and host version information It can also attempt to read files and write to the server as well Getting S

SQL Injection Vulnerability on PhpIPAM v1.4.4

CVE-2022-23046 PhpIPAM v144 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-searchphp Installation Build git clone githubcom/dnr6419/CVE-2022-23046git cd CVE-2022-23046 && docker-compose up -d pip3(or pip) install -r requirementstxt py