EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-16T13:15:24

Updated: 2024-08-03T11:02:14.673Z

Reserved: 2022-08-29T00:00:00

Link: CVE-2022-38846

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-16T14:15:09.670

Modified: 2024-11-21T07:17:10.150

Link: CVE-2022-38846

cve-icon Redhat

No data.