EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-16T13:15:24

Updated: 2022-09-16T13:15:24

Reserved: 2022-08-29T00:00:00


Link: CVE-2022-38846

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-16T14:15:09.670

Modified: 2022-09-17T02:26:16.420


Link: CVE-2022-38846

JSON object: View

cve-icon Redhat Information

No data.

CWE