VYPR

CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag

VariantIncompleteLikelihood: Medium

Description

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (46)

page 3 of 3
  • CVE-2023-2876LowJun 13, 2023
    risk 0.20cvss 3.1epss 0.00

    Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0…

  • CVE-2019-25091LowDec 27, 2022
    risk 0.17cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in nsupdate.info. This affects an unknown part of the file src/nsupdate/settings/base.py of the component CSRF Cookie Handler. The manipulation of the argument CSRF_COOKIE_HTTPONLY leads to cookie without 'httponly' flag.…

  • CVE-2026-57948MedJun 29, 2026
    risk 0.00cvss 6.8epss 0.00

    Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP.…

  • CVE-2022-4630MedDec 21, 2022
    risk 0.00cvss 5.3epss 0.01

    Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.

  • CVE-2021-3706HigSep 15, 2021
    risk 0.00cvss 7.5epss 0.01

    adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag

  • CVE-2010-4312Nov 26, 2010
    risk 0.00cvss —epss 0.02

    The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.