CVE-2025-27453

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.
Configurations

No configuration.

History

No history.

Information

Published : 2025-07-03 12:15

Updated : 2025-07-03 15:13


NVD link : CVE-2025-27453

Mitre link : CVE-2025-27453

CVE.ORG link : CVE-2025-27453


JSON object : View

Products Affected

No product.

CWE
CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag