Sensitive Cookie Without 'HttpOnly' Flag in filegator/filegator


Reported on

Sep 27th 2021


HTTPOnly attribute is not set for session cookies in the application.

Proof of Concept


When a cookie doesn’t have an HttpOnly flag, it can be accessed through JavaScript, which means that an XSS could lead to cookies being stolen. These include session cookies that can make it easier to achieve account/session takeover.

We have contacted a member of the filegator team and are waiting to hear back a year ago
Milos Stojanovic validated this vulnerability a year ago
0xdhinu has been awarded the disclosure bounty
The fix bounty is now up for grabs
Milos Stojanovic confirmed that a fix has been merged on e79fc7 a year ago
Milos Stojanovic has been awarded the fix bounty
to join this conversation