Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18180 | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. |
Solution
Users are strongly recommended to upgrade to the latest release of Media Server (>= 1.5).
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 12 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. | |
| Title | Cookie missing HttpOnly flag | |
| Weaknesses | CWE-1004 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2025-06-13T06:24:54.677Z
Reserved: 2025-06-03T05:55:52.772Z
Link: CVE-2025-49189
Updated: 2025-06-12T14:22:51.620Z
Status : Awaiting Analysis
Published: 2025-06-12T14:15:31.423
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-49189
No data.
OpenCVE Enrichment
No data.
EUVD