Impact
PHPIPAM contains a flaw that lets an authenticated user with API access include and run arbitrary PHP files from the server’s filesystem. The vulnerability is a classic local file inclusion, classified as CWE‑98, that may lead to execution of malicious code and compromise of the application environment.
Affected Systems
The affected system is the PHPIPAM network management application from vendor phpipam. No specific product version is listed, indicating that all installations with the vulnerable by default, so only deployments that have activated it are at risk.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity rating, while the EPSS score of less than 1 % reflects a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated API access and the API must be enabled, the primary attack vector is an attacker who first authenticates to the system and then crafts API requests that trigger the inclusion of a chosen PHP file.
OpenCVE Enrichment