PT-2025-12055 · Phpipam · Phpipam
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-10718
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpipam/phpipam versions 1.5.1 through 1.6.x
Description
The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information.
Recommendations
For versions 1.5.1 through 1.6.x, update to version 1.7.0 to resolve the issue.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpipam