In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Jun 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phpipam
Phpipam phpipam |
|
Weaknesses | CWE-319 | |
CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
Vendors & Products |
Phpipam
Phpipam phpipam |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0. | |
Title | Cookie without Secure attribute in phpipam/phpipam | |
Weaknesses | CWE-614 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:07.285Z
Updated: 2025-03-20T18:31:14.232Z
Reserved: 2024-11-01T22:59:44.199Z
Link: CVE-2024-10718

Updated: 2025-03-20T17:52:23.387Z

Status : Analyzed
Published: 2025-03-20T10:15:18.650
Modified: 2025-06-27T15:29:49.470
Link: CVE-2024-10718

No data.