In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.
The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Professional_service_automation | Connectwise | * | 2026.1 (excluding) |