Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqgp-549c-xhq5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

EPSS

Процентиль: 54%
0.00312
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1004
CWE-732
CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.

EPSS

Процентиль: 54%
0.00312
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1004
CWE-732
CWE-79