In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NPhpipam
APPPhpipam< 1.7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2022-41443CRITICAL9.8PL ✓same product
Header injection w phpIPAM v1.5.0 — komponent ripe-query.php
CVE-2019-16693CRITICAL9.8PL ✓same product
SQL injection w phpIPAM 1.4 via parametr 'table' w module custom-fields
CVE-2019-16692CRITICAL9.8PL ✓same product
SQL injection w phpIPAM 1.4 — moduł custom-fields/filter-result.php
CVE-2019-16694CRITICAL9.8PL ✓same product
SQL Injection w phpIPAM 1.4 – parametr 'table' w edycji pól
CVE-2019-16695CRITICAL9.8PL ✓same product
SQL injection w phpIPAM 1.4 przez parametr table w filtrze pól własnych