Description
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2013-5764 Vulnerability (CVE-2013-5764)
Internet Information Services Other Vulnerability (CVE-2002-0869)
WordPress Plugin WP-Lytebox 'pg' Parameter Local File Inclusion (1.3)
WordPress Plugin Quizlord Cross-Site Scripting (2.0)
WordPress Plugin BetterDocs-Best Documentation & Knowledge Base Cross-Site Scripting (1.8.4)