adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/ac7fd77b-b31b-4d02-aebd-f89ecbae3fce | issue tracking patch exploit third party advisory |
https://github.com/pi-hole/adminlte/commit/cf8602eedd4a31eadb72372fc878c12d342f8600 | third party advisory patch |