Loading HuntDB...

Session Cookie without HttpOnly and secure flag set

None
S
Stellar.org
Submitted None
Reported by k4yy1s

Vulnerability Details

Technical details and impact analysis

Violation of Secure Design Principles
vulnerable URL: www.stellar.org The PHPSESSID cookie does not have the HTTPOnly flag set. When a cookie is set with the HTTPOnly flag, it instructs the browser that the cookie can only accessed by the server and not by client-side scripts. This is an important security protection for session cookies. reference : https://hackerone.com/reports/75357 {F193713}

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Violation of Secure Design Principles