CVE-2016-2304
MEDIUMEcava Integraxor < 4.2.4502 - Information Disclosure
Title source: ruleDescription
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Scores
CVSS v3
4.3
EPSS
0.0034
EPSS Percentile
56.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
Status
draft
Affected Products (1)
ecava/integraxor
< 4.2.4502
Timeline
Published
Apr 22, 2016
Tracked Since
Feb 18, 2026