The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. | |
Title | Cookie missing HttpOnly flag | |
Weaknesses | CWE-1004 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: SICK AG
Published: 2025-06-12T14:03:39.842Z
Updated: 2025-06-13T06:24:54.677Z
Reserved: 2025-06-03T05:55:52.772Z
Link: CVE-2025-49189

Updated: 2025-06-12T14:22:51.620Z

Status : Awaiting Analysis
Published: 2025-06-12T14:15:31.423
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-49189

No data.