SYM_PHP_0009 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki
Sensitive Cookie Without 'HttpOnly' Flag
Property | Value |
---|---|
Language | |
Severity | |
CWE | CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag |
OWASP | A05:2021 - Security Misconfiguration |
Confidence Level | Low |
Impact Level | Low |
Likelihood Level | Low |
Description
Found a configuration file where the lifetime attribute is over 30 minutes.