Sensitive Cookie Without 'HttpOnly' Flag in filegator/filegator

Valid

Reported on

Sep 27th 2021


Description

HTTPOnly attribute is not set for session cookies in the application.

Proof of Concept

https://ibb.co/R950Vxj

Impact

When a cookie doesn’t have an HttpOnly flag, it can be accessed through JavaScript, which means that an XSS could lead to cookies being stolen. These include session cookies that can make it easier to achieve account/session takeover.

We have contacted a member of the filegator team and are waiting to hear back 2 months ago
We have contacted a member of the filegator team and are waiting to hear back 2 months ago
Milos Stojanovic validated this vulnerability 2 months ago
0xdhinu has been awarded the disclosure bounty
The fix bounty is now up for grabs
Milos Stojanovic confirmed that a fix has been merged on e79fc7 2 months ago
Milos Stojanovic has been awarded the fix bounty