Description

phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the database export functionality. The generate-mysql.php function, located in the /app/admin/import-export/ endpoint, allows remote attackers to trigger large database dump downloads via crafted HTTP GET requests if an administrator has an active session.

INFO

Published Date :

2025-12-08T00:00:00.000Z

Last Modified :

2025-12-08T17:17:44.445Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-60912 vulnerability.

Vendors Products
Phpipam
  • Phpipam
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-60912.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact