An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Znuny | Znuny | * | 7.1.3 (including) |
| Znuny | Ubuntu | oracular | * |
| Znuny | Ubuntu | upstream | * |