3.5
CVE-2023-4654
- EPSS 0.29%
- Veröffentlicht 31.08.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:35:37
- CVE-Watchlists
- Unerledigt
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in instantsoft/icms2
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Instantcms ≫ Instantcms Version < 2.16.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.203 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.5 | 2.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
|
| security@huntr.dev | 2.6 | 1.2 | 1.4 |
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
|
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set.
https://github.com/instantsoft/icms2/commit/ca5f150da11d9caae86638885137afe35bcc3592
https://huntr.dev/bounties/56432a75-af43-4b1a-9307-bd8de568351b