← back
CVE-2022-23046

CVE-2022-23046

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 25%
from disclosure to weapon3 days
Published on NVDJan 19
1st PoC+3d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php
Affected products
n/a · PhpIPAM
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.