ZeroHour

CVE-2024-10718

PoC
CVSS 3.1
7.5 high
EPSS
<1%p25
Published
()
Modified
Description

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

Vendors
phpipam
Products
phpipam
Weakness
CWE-614, CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.