CVE-2025-27453

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.
Configurations

No configuration.

History

03 Jul 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-03 12:15

Updated : 2025-07-03 15:13


NVD link : CVE-2025-27453

Mitre link : CVE-2025-27453

CVE.ORG link : CVE-2025-27453


JSON object : View

Products Affected

No product.

CWE
CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag