Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/401661ee-40e6-4ee3-a925-3716b96ece5c | exploit third party advisory patch |
https://github.com/lirantal/daloradius/commit/6878619dc661b3009429777a1aeeb383ddc0166b | third party advisory patch |