PT-2022-11290 · Connx · Connx

L00Neyhacker

·

Published

2022-06-14

·

Updated

2022-06-22

·

CVE-2021-40649

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Connx version 6.2.0.1269
Description The issue arises when a cookie is issued by the application without having the HttpOnly flag set. This flag is crucial as it helps mitigate the risk of client-side script accessing the cookie, thereby reducing the risk of session hijacking.
Recommendations For Connx version 6.2.0.1269, consider configuring the application to set the HttpOnly flag for all cookies to prevent potential session hijacking attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40649

Affected Products

Connx