Vulnerability CVE-2024-0349


Published: 2024-01-09   Modified: 2024-01-10

Description:
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to sensitive cookie without secure attribute. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-250117 was assigned to this vulnerability.

Type:

CWE-614

(Sensitive Cookie in HTTPS Session Without 'Secure' Attribute)

 References:
https://vuldb.com/?id.250117
https://vuldb.com/?ctiid.250117
https://mega.nz/file/TU1X3TIQ#7bPvxEP0KrdoDZVg-dqinNC5fEQrG5uu58jWzPGh904

Copyright 2024, cxsecurity.com

 

Back to Top