|  |  | 
closedb();
?>
| Vulnerability CVE-2020-7988Published: 2020-03-04
 
 
	Type:
		| Description: |  
		| An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens. |  
 CWE-352(Cross-Site Request Forgery (CSRF))
				 CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)| CVSS Base Score | Impact Subscore | Exploitability Subscore |  
							| 6.8/10 | 6.4/10 | 8.6/10 | 
 
						| Exploit range | Attack complexity | Authentication |  
						| Remote | Medium | No required |  
						| Confidentiality impact | Integrity impact | Availability impact |  
						| Partial | Partial | Partial | 
 
|  References: |  
| https://pastebin.com/ZPECbgZb https://phpipam.net/news/phpipam-v1-5-released/ | 
 |  |  |  Copyright 2025, cxsecurity.com
  
     |  |  |