HIGH🇵🇱 Wersja polska

CVE-2024-10718

CVSS 7.5v3.1pub. 2025-03-20upd. 2025-06-27

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Phpipam

    APP
    Phpipam
    < 1.7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-41443CRITICAL9.8PL ✓same product

Header injection w phpIPAM v1.5.0 — komponent ripe-query.php

CVE-2019-16693CRITICAL9.8PL ✓same product

SQL injection w phpIPAM 1.4 via parametr 'table' w module custom-fields

CVE-2019-16692CRITICAL9.8PL ✓same product

SQL injection w phpIPAM 1.4 — moduł custom-fields/filter-result.php

CVE-2019-16694CRITICAL9.8PL ✓same product

SQL Injection w phpIPAM 1.4 – parametr 'table' w edycji pól

CVE-2019-16695CRITICAL9.8PL ✓same product

SQL injection w phpIPAM 1.4 przez parametr table w filtrze pól własnych