ZeroHour

CVE-2020-27658

PoC
CVSS 3.1
6.1 medium
EPSS
1%p69
Published
()
Modified
Description

Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

Vendors
synology
Products
router manager
Weakness
CWE-1004, CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.