We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-10718

Cookie without Secure attribute in phpipam/phpipam



Description

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

Reserved 2024-11-01 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Product status

Any version before 1.7.0
affected

References

huntr.com/bounties/725bce8f-328f-4fbc-acf5-46ea920cd3c1

github.com/...ommit/ddf70ef6801442eb8b0be5eea829e470e653c70e

cve.org (CVE-2024-10718)

nvd.nist.gov (CVE-2024-10718)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-10718

Support options

Helpdesk Chat, Email, Knowledgebase