An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Znuny | Ubuntu | upstream | * |