
CVE-2022-1224 – Improper Authorization in phpipam/phpipam
https://notcve.org/view.php?id=CVE-2022-1224
04 Apr 2022 — Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. Una Autorización Inapropiada en el repositorio de GitHub phpipam/phpipam versiones anteriores a 1.4.6 • https://github.com/phpipam/phpipam/commit/f6a49fd9f93b7d7e0a4fbf1d35338502eed35953 • CWE-285: Improper Authorization CWE-863: Incorrect Authorization •

CVE-2021-35438
https://notcve.org/view.php?id=CVE-2021-35438
23 Jun 2021 — phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator. phpIPAM versión 1.4.3, permite un ataque de tipo XSS reflejado por medio de los archivos app/dashboard/widgets/ipcalc-result.php y app/tools/ip-calculator/result.php de la calculadora de IP • https://github.com/phpipam/phpipam/issues/3351 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •