CVE-2024-10718

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
Configurations

No configuration.

History

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-03-20 10:15


NVD link : CVE-2024-10718

Mitre link : CVE-2024-10718

CVE.ORG link : CVE-2024-10718


JSON object : View

Products Affected

No product.

CWE
CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute