Vulnerability Description
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
CVSS Score
5.7
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmyfaq | Phpmyfaq | < 3.2.1 |
Related Weaknesses (CWE)
References
- https://github.com/thorsten/phpmyfaq/commit/fdacff14acd5e69841068f0e32b59e2d1b1dPatch
- https://huntr.com/bounties/ec44bcba-ae7f-497a-851e-8165ecf56945ExploitPatchThird Party Advisory
- https://github.com/thorsten/phpmyfaq/commit/fdacff14acd5e69841068f0e32b59e2d1b1dPatch
- https://huntr.com/bounties/ec44bcba-ae7f-497a-851e-8165ecf56945ExploitPatchThird Party Advisory
FAQ
What is CVE-2023-5866?
CVE-2023-5866 is a vulnerability with a CVSS score of 5.7 (MEDIUM). Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.2.1.
How severe is CVE-2023-5866?
CVE-2023-5866 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5866?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmyfaq Phpmyfaq.