Back

HIGH

ITarian - Session cookie not protected by HttpOnly flag

Published Jun 8, 2022

Description

Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination with a successful Cross-Site Scripting attack on a user.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner DIVD
Published Jun 8, 2022
Updated Mar 11, 2025
Reserved Feb 14, 2022
CISA Vulnrichment
Updated Jul 26, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner DIVD
Published Jun 8, 2022
Updated Mar 11, 2025
Exploited since n/a
EUVD-2022-29894