VYPR
Medium severity4.3NVD Advisory· Published Jun 29, 2022· Updated Jun 17, 2026

CVE-2021-40642

CVE-2021-40642

Description

Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribute via textpattern/lib/txplib_misc.php. The secure flag is not set for txp_login session cookie in the application. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:textpattern:textpattern:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:textpattern:textpattern:*:*:*:*:*:*:*:*range: <=4.8.7
    • (no CPE)
    • (no CPE)range: <=4.8.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.