Sensitive Cookie Without 'HttpOnly' Flag in filegator/filegator


Reported on

Sep 27th 2021


HTTPOnly attribute is not set for session cookies in the application.

Proof of Concept


When a cookie doesn’t have an HttpOnly flag, it can be accessed through JavaScript, which means that an XSS could lead to cookies being stolen. These include session cookies that can make it easier to achieve account/session takeover.

We have contacted a member of the filegator team and are waiting to hear back 2 years ago
Milos Stojanovic validated this vulnerability 2 years ago
0xdhinu has been awarded the disclosure bounty
The fix bounty is now up for grabs
Milos Stojanovic marked this as fixed with commit e79fc7 2 years ago
Milos Stojanovic has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation