Lucene search

K
cvelistMitreCVELIST:CVE-2013-4617
HistoryNov 27, 2013 - 6:00 p.m.

CVE-2013-4617

2013-11-2718:00:00
mitre
www.cve.org

AI Score

6.1

Confidence

Low

EPSS

0.006

Percentile

78.5%

Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

AI Score

6.1

Confidence

Low

EPSS

0.006

Percentile

78.5%

Related for CVELIST:CVE-2013-4617