SYM_PHP_0009 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki

Sensitive Cookie Without 'HttpOnly' Flag

Property Value
Language php
Severity low
CWE CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag
OWASP A05:2021 - Security Misconfiguration
Confidence Level Low
Impact Level Low
Likelihood Level Low

Description

Found a configuration file where the lifetime attribute is over 30 minutes.