First published: Sun Dec 11 2022(Updated: )
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | <3.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4409 has been assigned a medium severity rating due to the potential exposure of sensitive cookie information.
To fix CVE-2022-4409, update phpMyFAQ to version 3.1.9 or later to ensure that sensitive cookies are set with the 'Secure' attribute.
CVE-2022-4409 affects all versions of phpMyFAQ prior to 3.1.9.
The potential impacts of CVE-2022-4409 include unauthorized access to sensitive session cookies, which could lead to session hijacking.
As of now, there are no publicly disclosed exploits specifically targeting CVE-2022-4409.