CVE-2022-4409: phpMyFAQ has insecure HTTP cookies
7.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.22421%
CWE
Published
12/11/2022
Updated
6/27/2023
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| thorsten/phpmyfaq | composer | < 3.1.9 | 3.1.9 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from cookies not having the Secure attribute when served over HTTPS. The critical functions are: 1) Session::setCookie() where cookie parameters are defined - pre-fix it used a flawed protocol check. 2) Bootstrap initialization where session cookie settings were configured without proper secure flag handling. The patches in commit c16cc2b specifically modify these areas to implement HTTPS-aware secure cookie attributes, confirming these functions' involvement.