Impact
The vulnerability in phpIPAM versions through 1.8.3 arises from a missing authorization check in customer, location, and NAT pages. Because Subnets::check_permission is omitted, an authenticated low‑privilege user can request these pages and read IP addresses, CIDRs, hostnames, and MAC addresses that should be restricted. This creates a data‑disclosure flaw (CWE‑862) that allows an attacker to map internal network details without code execution.
Affected Systems
The flaw affects all phpIPAM installations running version 1.8.3 or earlier. The affected product is identified as phpIPAM by the CNA, and the version string is unspecified beyond the threshold, so users should apply any patch later than 1.8.3.
Risk and Exploitability
The CVSS score of 5.3 places it in the medium severity range, and the EPSS score is not reported, implying no known active exploit. The vulnerability requires an authenticated session and is web‑based, so any logged‑in user with basic privileges could exploit it. While it does not compromise system functionality, the exposed network address information can aid attackers in planning further exploits. The vulnerability is not in the CISA KEV catalog, suggesting limited or zero real‑world exploitation to date.
OpenCVE Enrichment