Description
EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Verve Meta Boxes TimThumb Arbitrary File Upload (1.2.8)
WordPress Plugin Backup and Staging by WP Time Capsule Security Bypass (1.21.15)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8393)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-29004)