VYPR

CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag

VariantIncompleteLikelihood: Medium

Description

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (44)

page 2 of 3
  • CVE-2026-25733HigFeb 25, 2026
    risk 0.40cvss 7.3epss 0.00

    Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Custom Rules…

  • CVE-2022-25172MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.01

    An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack,…

  • CVE-2020-6267MedJul 14, 2020
    risk 0.35cvss 5.4epss 0.01

    Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.

  • CVE-2025-12031MedOct 21, 2025
    risk 0.34cvss 5.3epss 0.00

    HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-27453MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

  • CVE-2025-49189MedJun 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.

  • CVE-2024-6739MedJul 15, 2024
    risk 0.34cvss 5.3epss 0.00

    The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.

  • CVE-2026-39338MedApr 7, 2026
    risk 0.33cvss 6.1epss 0.00

    ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it…

  • CVE-2026-25736MedFeb 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Custom RSE Attribute…

  • CVE-2026-25735MedFeb 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Identity Name of the…

  • CVE-2026-25734MedFeb 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the RSE metadata of the…

  • CVE-2026-11956LowJun 11, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can lead to sensitive cookie without secure attribute. The attack can be launched…

  • CVE-2022-43845LowSep 25, 2024
    risk 0.24cvss 3.7epss 0.00

    IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie.

  • CVE-2022-33167LowJul 30, 2024
    risk 0.24cvss 3.7epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive…

  • CVE-2021-34563LowAug 31, 2021
    risk 0.21cvss 3.3epss 0.00

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.

  • CVE-2025-42909LowOct 14, 2025
    risk 0.20cvss 3.0epss 0.00

    SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and…

  • CVE-2023-4217LowNov 2, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and…

  • CVE-2023-4228LowAug 24, 2023
    risk 0.20cvss 3.1epss 0.00

    A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data…

  • CVE-2023-2876LowJun 13, 2023
    risk 0.20cvss 3.1epss 0.00

    Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0…

  • CVE-2019-25091LowDec 27, 2022
    risk 0.17cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag.…