HIGH🇬🇧 English

CVE-2024-10718

CVSS 7.5v3.1pub. 2025-03-20upd. 2025-06-27

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Phpipam

    APP
    Phpipam
    < 1.7.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2022-41443CRITICAL9.8PL ✓ten sam produkt

Header injection w phpIPAM v1.5.0 — komponent ripe-query.php

CVE-2019-16693CRITICAL9.8PL ✓ten sam produkt

SQL injection w phpIPAM 1.4 via parametr 'table' w module custom-fields

CVE-2019-16692CRITICAL9.8PL ✓ten sam produkt

SQL injection w phpIPAM 1.4 — moduł custom-fields/filter-result.php

CVE-2019-16694CRITICAL9.8PL ✓ten sam produkt

SQL Injection w phpIPAM 1.4 – parametr 'table' w edycji pól

CVE-2019-16695CRITICAL9.8PL ✓ten sam produkt

SQL injection w phpIPAM 1.4 przez parametr table w filtrze pól własnych