Sensitive Cookie Without 'HttpOnly' Flag
CWE-1004 · Variant · Incomplete
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.