CVE-2025-24318

CVSS v3 Score
6.8
Medium

Vulnerability Description

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

CVSS:6.5(Medium)

Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.

CVSS:6.5(Medium)

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts...

CVSS:6.3(Medium)

Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.

CVSS:7.4(High)

adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag

CVSS:6.1(Medium)

Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensi...

CVSS:6.1(Medium)

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.