CVE-2022-38846

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:espocrm:espocrm:7.1.8:*:*:*:*:*:*:*

History

21 Nov 2024, 07:17

Type Values Removed Values Added
References () https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-missing-secure-flag-1664bac5ffe4 - Exploit, Third Party Advisory () https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-missing-secure-flag-1664bac5ffe4 - Exploit, Third Party Advisory

Information

Published : 2022-09-16 14:15

Updated : 2024-11-21 07:17


NVD link : CVE-2022-38846

Mitre link : CVE-2022-38846

CVE.ORG link : CVE-2022-38846


JSON object : View

Products Affected

espocrm

  • espocrm
CWE
CWE-319

Cleartext Transmission of Sensitive Information