CVE-2023-5866: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5866?
CVE-2023-5866 is a vulnerability in the GitHub repository thorsten/phpmyfaq that allows sensitive cookies to be transmitted over an insecure HTTPS session without the 'Secure' attribute.
What is the severity of CVE-2023-5866?
CVE-2023-5866 is classified as a medium severity vulnerability with a severity score of 6.3.
How does CVE-2023-5866 affect thorsten/phpmyfaq?
CVE-2023-5866 affects thorsten/phpmyfaq versions prior to 3.2.1.
How can I fix CVE-2023-5866?
To fix CVE-2023-5866, upgrade thorsten/phpmyfaq to version 3.2.1 or later.
Where can I find more information about CVE-2023-5866?
More information about CVE-2023-5866 can be found at the following references: [huntr.com](https://huntr.com/bounties/ec44bcba-ae7f-497a-851e-8165ecf56945), [GitHub commit](https://github.com/thorsten/phpmyfaq/commit/fdacff14acd5e69841068f0e32b59e2d1b1d0d55), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-5866).