CVE-2025-49189
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via cl
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.
MEDIUM · CVSS 5.3
EPSS 0.00245
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules0
YARA rules0