CVE-2022-38846

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:espocrm:espocrm:7.1.8:*:*:*:*:*:*:*

History

21 Nov 2024, 07:17

Type Values Removed Values Added
References () https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-missing-secure-flag-1664bac5ffe4 - Exploit, Third Party Advisory () https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-missing-secure-flag-1664bac5ffe4 - Exploit, Third Party Advisory

17 Sep 2022, 02:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
References (MISC) https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-missing-secure-flag-1664bac5ffe4 - (MISC) https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-missing-secure-flag-1664bac5ffe4 - Exploit, Third Party Advisory
CPE cpe:2.3:a:espocrm:espocrm:7.1.8:*:*:*:*:*:*:*
CWE CWE-319

16 Sep 2022, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-16 14:15

Updated : 2024-11-21 07:17


NVD link : CVE-2022-38846

Mitre link : CVE-2022-38846

CVE.ORG link : CVE-2022-38846


JSON object : View

Products Affected

espocrm

  • espocrm
CWE
CWE-319

Cleartext Transmission of Sensitive Information