CVE-2022-38846: Medium severity espocrm vulnerability
Published Sep 16, 2022
·Updated
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
Affected Software
1 affected component
EspoCRM EspoCRM=7.1.8
Event History
Sep 16, 2022
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
Description
Frequently Asked Questions
1
What is CVE-2022-38846?
CVE-2022-38846 is a vulnerability in EspoCRM version 7.1.8 that allows the browser to send plain text cookies over an insecure channel (HTTP).
2
How can an attacker exploit CVE-2022-38846?
An attacker can exploit CVE-2022-38846 by capturing the cookie from the insecure channel using a man-in-the-middle (MITM) attack.
3
What is the severity of CVE-2022-38846?
CVE-2022-38846 has a severity level of medium with a CVSS score of 5.9.
4
How can I fix CVE-2022-38846?
To fix CVE-2022-38846, update EspoCRM to a version that includes the missing secure flag in the cookies.
5
Is EspoCRM version 7.1.8 affected by CVE-2022-38846?
Yes, EspoCRM version 7.1.8 is affected by CVE-2022-38846.