Логотип exploitDog
bind:CVE-2021-40642
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-40642

Количество 3

Количество 3

nvd логотип

CVE-2021-40642

больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-40642

больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitiv ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w43v-qr8x-xq75

больше 3 лет назад

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-40642

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-40642

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitiv ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w43v-qr8x-xq75

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу