mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
20 lines
924 B
Markdown
20 lines
924 B
Markdown
### [CVE-2021-34563](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34563)
|
|

|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://cert.vde.com/en-us/advisories/vde-2021-027
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|