cve/2025/CVE-2025-27453.md
2025-09-29 21:09:30 +02:00

781 B

CVE-2025-27453

Description

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

POC

Reference

Github