EspoCRM version 7.1.8 is vulnerable to Missing Secure...
Moderate severity
Unreviewed
Published
Sep 17, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Sep 16, 2022
Published to the GitHub Advisory Database
Sep 17, 2022
Last updated
Jan 28, 2023
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
References