Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-38846

EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insecure channel (HTTP). An attacker may capture the cookie from the insecure channel using MITM attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.1%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2022-38846
  • Espocrm » Espocrm » Version: 7.1.8
    cpe:2.3:a:espocrm:espocrm:7.1.8


Contact Us

Shodan ® - All rights reserved