CWE-1004
44 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium
Sensitive Cookie Without 'HttpOnly' Flag
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scriptin...Show more |
CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an attacker can inject malicious JavaScript into...Show more |
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. |
Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise. |
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by intercepting data transmissions during an HTTP...Show more |
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. T...Show more |
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive...Show more |
1Ibm 2Security Directory Integrator Security Verify Directory IntegratorJun 17, 2026 Jul 30, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker...Show more |
1Syrotech 1Sy Gpon 1110 Wdont Firmware Jun 17, 2026 Jul 26, 2024 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker with remote access could exploit thi...Show more |
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS. |
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially...Show more |
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead...Show more |
1Abb 3Rex640 Pcl1 Firmware Rex640 Pcl2 FirmwareRex640 Pcl3 FirmwareJun 17, 2026 Jun 13, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects RE...Show more |
1Johnsoncontrols 1Metasys System Configuration Tool Jun 17, 2026 Feb 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie. |
A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSR...Show more |
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. |
1Inhandnetworks 1Ir302 Firmware Jun 17, 2026 May 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and...Show more |
1Businessdnasolutions 1Topease Jun 17, 2026 Nov 30, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authentica...Show more |
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin...Show more |
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag |