HIGH
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq
Published Dec 11, 2022
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<3.1.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Thorsten | Thorsten/phpmyfaq | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (3)
References (5)
- https://github.com/advisories/GHSA-wpgc-5cr5-h9gg Advisory
- https://github.com/thorsten/phpMyFAQ/commit/c16cc2bbe2687f75aa1204b804483091fae43cba
- https://github.com/thorsten/phpmyfaq/commit/8b47f38 PatchThird Party Advisory
- https://huntr.dev/bounties/5915ed4c-5fe2-42e7-8fac-5dd0d032727c ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4409
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-wpgc-5cr5-h9gg | Advisory | |
| https://github.com/thorsten/phpMyFAQ/commit/c16cc2bbe2687f75aa1204b804483091fae43cba | ||
| https://github.com/thorsten/phpmyfaq/commit/8b47f38 | PatchThird Party Advisory | |
| https://huntr.dev/bounties/5915ed4c-5fe2-42e7-8fac-5dd0d032727c | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4409 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Dec 11, 2022
Updated Apr 14, 2025
Reserved Dec 11, 2022
Link CVE-2022-4409
CISA Vulnrichment
GHSA-WPGC-5CR5-H9GG Updated Apr 14, 2025