For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published: 2020-04-02T19:46:29

Updated: 2024-08-05T02:02:39.846Z

Reserved: 2019-11-15T00:00:00

Link: CVE-2019-19003

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-02T20:15:14.097

Modified: 2024-11-21T04:33:58.477

Link: CVE-2019-19003

cve-icon Redhat

No data.