For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-8656 | For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-08-05T02:02:39.846Z
Reserved: 2019-11-15T00:00:00
Link: CVE-2019-19003
No data.
Status : Modified
Published: 2020-04-02T20:15:14.097
Modified: 2024-11-21T04:33:58.477
Link: CVE-2019-19003
No data.
OpenCVE Enrichment
No data.
EUVD