CVE-2024-10718

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*

History

27 Jun 2025, 15:29

Type Values Removed Values Added
First Time Phpipam phpipam
Phpipam
CPE cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*
CWE CWE-319
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
References () https://github.com/phpipam/phpipam/commit/ddf70ef6801442eb8b0be5eea829e470e653c70e - () https://github.com/phpipam/phpipam/commit/ddf70ef6801442eb8b0be5eea829e470e653c70e - Patch
References () https://huntr.com/bounties/725bce8f-328f-4fbc-acf5-46ea920cd3c1 - () https://huntr.com/bounties/725bce8f-328f-4fbc-acf5-46ea920cd3c1 - Exploit, Third Party Advisory
Summary
  • (es) En la versión 1.5.1 de phpipam/phpipam, el atributo "Secure" para cookies sensibles en sesiones HTTPS no está configurado. Esto podría provocar que el agente de usuario envíe dichas cookies en texto plano a través de una sesión HTTP, lo que podría exponer información sensible. El problema se solucionó en la versión 1.7.0.

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-06-27 15:29


NVD link : CVE-2024-10718

Mitre link : CVE-2024-10718

CVE.ORG link : CVE-2024-10718


JSON object : View

Products Affected

phpipam

  • phpipam
CWE
CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

CWE-319

Cleartext Transmission of Sensitive Information