CVE-2025-27453 Information
Jul 04, 2025
cve
Description
The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore the cookie can be accessed by other sources such as JavaScript.
Reference
https://sick.com/psirt https://sick.com/psirt https://www.cisa.gov/resources-tools/resources/ics-recommended-practices https://www.endress.com https://www.first.org/cvss/calculator/3.1 https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf
Related CNNVD
CNNVD-202507-273 (Published: 2025-07-03)
Share on: