Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mj67-2mvx-f778

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

EPSS

Процентиль: 17%
0.00054
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-319
CWE-614

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

CVSS3: 7.5
debian
11 месяцев назад

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive c ...

EPSS

Процентиль: 17%
0.00054
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-319
CWE-614