In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NPhpipam
APPPhpipam< 1.7.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2022-41443CRITICAL9.8PL ✓ten sam produkt
Header injection w phpIPAM v1.5.0 — komponent ripe-query.php
CVE-2019-16693CRITICAL9.8PL ✓ten sam produkt
SQL injection w phpIPAM 1.4 via parametr 'table' w module custom-fields
CVE-2019-16692CRITICAL9.8PL ✓ten sam produkt
SQL injection w phpIPAM 1.4 — moduł custom-fields/filter-result.php
CVE-2019-16694CRITICAL9.8PL ✓ten sam produkt
SQL Injection w phpIPAM 1.4 – parametr 'table' w edycji pól
CVE-2019-16695CRITICAL9.8PL ✓ten sam produkt
SQL injection w phpIPAM 1.4 przez parametr table w filtrze pól własnych