CVE-2025-49189

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.
Configurations

No configuration.

History

12 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 14:15

Updated : 2025-06-12 16:06


NVD link : CVE-2025-49189

Mitre link : CVE-2025-49189

CVE.ORG link : CVE-2025-49189


JSON object : View

Products Affected

No product.

CWE
CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag