CVE Vulnerabilities

CVE-2025-27453

Sensitive Cookie Without 'HttpOnly' Flag

Published: Jul 03, 2025 | Modified: Jan 29, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

Weakness

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Affected Software

NameVendorStart VersionEnd Version
Meac300-fnade4_firmwareEndress*0.16.0 (including)

Potential Mitigations

References