3.5
CVE-2023-4654
- EPSS 0.04%
- Veröffentlicht 31.08.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:35:37
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Instantcms ≫ Instantcms Version < 2.16.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 2.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
|
| security@huntr.dev | 2.6 | 1.2 | 1.4 |
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
|
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the user agent to send those cookies in plaintext over an HTTP session.