Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w43v-qr8x-xq75

Опубликовано: 30 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

EPSS

Процентиль: 31%
0.00115
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

CVSS3: 4.3
debian
больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitiv ...

EPSS

Процентиль: 31%
0.00115
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-565