Sensitive Cookie Without 'HttpOnly' Flag in slackero/phpwcms
Valid
Reported on
Aug 21st 2021
✍️ Description
HTTPOnly attribute is not set for session cookies in the application.
🕵️♂️ Proof of Concept
💥 Impact
When a cookie doesn’t have an HttpOnly flag, it can be accessed through JavaScript, which means that an XSS could lead to cookies being stolen. These include session cookies that can make it easier to achieve account/session takeover.
Occurrences
We have contacted a member of the
slackero/phpwcms
team and are waiting to hear back
2 years ago
@Oliver - small bug on our site, please try re-confirming the patch again.
Apologies for the inconvenience!
to join this conversation