CVE-2025-60912

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-08 15:15

Updated : 2025-12-10 17:36


NVD link : CVE-2025-60912

Mitre link : CVE-2025-60912

CVE.ORG link : CVE-2025-60912


JSON object : View

Products Affected

phpipam

  • phpipam
CWE
CWE-352

Cross-Site Request Forgery (CSRF)