Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40642

Опубликовано: 29 июн. 2022
Источник: nvd
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:textpattern:textpattern:*:*:*:*:*:*:*:*
Версия до 4.8.7 (включая)

EPSS

Процентиль: 30%
0.00115
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 4.3
debian
больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitiv ...

CVSS3: 4.3
github
больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

EPSS

Процентиль: 30%
0.00115
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-311