{"id":"CVE-2018-1000869","details":"phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This vulnerability appears to have been fixed in 1.4.","modified":"2026-08-07T14:54:02.413665Z","published":"2018-12-20T17:29:00.737Z","references":[{"type":"FIX","url":"https://github.com/phpipam/phpipam/commit/856b10ca85a24c04ed8651f4e13f867ec78a353d"},{"type":"EVIDENCE","url":"https://github.com/phpipam/phpipam/issues/2344"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/phpipam/phpipam","events":[{"introduced":"d22e50224ad89ec31c329576a25ba6ec64903857"},{"last_affected":"d22e50224ad89ec31c329576a25ba6ec64903857"},{"fixed":"856b10ca85a24c04ed8651f4e13f867ec78a353d"}],"database_specific":{"cpe":"cpe:2.3:a:phpipam:phpipam:1.3.2:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.3.2"},{"last_affected":"1.3.2"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.3.2","v1.3.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000869.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}