Vulnerability Details Vulnerability Type Cross Site Scripting (XSS) Description phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via . Environment Setup Software: phpipam Version: 1.6 Tested on: Windows 10 Exploit Description phpipam 1.6 is vulnerable to reflected XSS due to improper input validation of the parameter in , allowing execution of arbitrary JavaScript in the browser. Steps to Reproduce 1. Access a phpipam instance. 2. Open the following PoC URL in a browser. 3. Observe the result: !PoC Screenshot