CVE-2025-22493
Last modified
CVE-2025-22493 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-22493?
How severe is CVE-2025-22493?
How do I fix CVE-2025-22493?
Are you affected by CVE-2025-22493?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
