CVE-2022-23046
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 25%
from disclosure to weapon3 days
Published on NVDJan 19
1st PoC+3d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Affected products
n/a · PhpIPAMpublic PoCs found — 6
exploitdbwww.exploit-db.com/exploits/50684unverifiedgithubgithub.com/dnr6419/CVE-2022-23046★ 4githubgithub.com/jcarabantes/CVE-2022-23046★ 1githubgithub.com/bernauers/CVE-2022-23046★ 1githubgithub.com/hadrian3689/phpipam_1.4.4★ 0cve_referencepacketstormsecurity.com/files/165683/PHPIPAM-1.4.4-SQL-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.