CVE-2024-10718

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpipam:phpipam:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-20 10:15

Updated : 2025-06-27 15:29


NVD link : CVE-2024-10718

Mitre link : CVE-2024-10718

CVE.ORG link : CVE-2024-10718


JSON object : View

Products Affected

phpipam

  • phpipam
CWE
CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

CWE-319

Cleartext Transmission of Sensitive Information