In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 27 Jun 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Phpipam
         Phpipam phpipam  | 
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Phpipam
         Phpipam phpipam  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0. | |
| Title | Cookie without Secure attribute in phpipam/phpipam | |
| Weaknesses | CWE-614 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_0
         
  | 
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:31:14.232Z
Reserved: 2024-11-01T22:59:44.199Z
Link: CVE-2024-10718
Updated: 2025-03-20T17:52:23.387Z
Status : Analyzed
Published: 2025-03-20T10:15:18.650
Modified: 2025-06-27T15:29:49.470
Link: CVE-2024-10718
No data.