Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-556p-rv4j-m787

Опубликовано: 17 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.

EPSS

Процентиль: 32%
0.00119
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.

EPSS

Процентиль: 32%
0.00119
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-319