← Back
CWE-1004

44 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium

Sensitive Cookie Without 'HttpOnly' Flag

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

JSON object

Loading...

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sick
1Media Server
Jun 17, 2026
Jun 12, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scriptin...Show more
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.Show less
1Phoenixcart
1Ce Phoenix Cart
Jun 17, 2026
Jun 2, 2025
N/A· v4
9.0 CRITICAL· v3
N/A· v2
CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into...Show more
CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into the testimonial description field. Once submitted, if the shop owner (admin) approves the testimonial, the script executes in the context of any user visiting the testimonial page. Because the session cookies are not marked with the `HttpOnly` flag, they can be exfiltrated by the attacker — potentially leading to account takeover. Version 1.1.0.3 fixes the issue.Show less
1Znuny
1Znuny
Jun 17, 2026
May 8, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
-
-
Jun 17, 2026
Feb 28, 2025
5.9 MEDIUM· v4
6.8 MEDIUM· v3
N/A· v2
Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.
-
-
Jun 17, 2026
Jan 20, 2025
8.6 HIGH· v4
N/A· v3
N/A· v2
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP...Show more
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and compromise the targeted system.Show less
1Avaiga
1Taipy
Jun 17, 2026
Oct 9, 2024
6.3 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. T...Show more
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Ibm
1Aspera Console
Jun 17, 2026
Sep 25, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive...Show more
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.Show less
1Ibm
2Security Directory Integrator
Security Verify Directory Integrator
Jun 17, 2026
Jul 30, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker...Show more
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 228587.Show less
1Syrotech
1Sy Gpon 1110 Wdont Firmware
Jun 17, 2026
Jul 26, 2024
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit thi...Show more
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit this by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to capture cookies and obtain sensitive information on the targeted system.Show less
1Openfind
2Mailaudit
Mailgates
Jun 17, 2026
Jul 15, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
1Moxa
1Eds G503 Firmware
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially...Show more
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation. Show less
1Moxa
1Iologik E4200 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead...Show more
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation. Show less
1Abb
3Rex640 Pcl1 Firmware
Rex640 Pcl2 FirmwareRex640 Pcl3 Firmware
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects RE...Show more
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1. Show less
1Johnsoncontrols
1Metasys System Configuration Tool
Jun 17, 2026
Feb 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
1Nsupdate
1Nsupdate.info
Jun 17, 2026
Dec 27, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSR...Show more
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag. It is possible to initiate the attack remotely. The name of the patch is 60a3fe559c453bc36b0ec3e5dd39c1303640a59a. It is recommended to apply a patch to fix this issue. The identifier VDB-216909 was assigned to this vulnerability.Show less
1Daloradius
1Daloradius
Jun 17, 2026
Dec 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
1Inhandnetworks
1Ir302 Firmware
Jun 17, 2026
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and...Show more
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.Show less
1Businessdnasolutions
1Topease
Jun 17, 2026
Nov 30, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authentica...Show more
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin...Show more
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.Show less
1Pi Hole
1Web Interface
Jun 17, 2026
Sep 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag