ZeroHour

CVE-2025-27453

CVSS 3.1
6.5 medium
EPSS
<1%p31
Published
()
Modified
Description

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

Vendors
endress
Products
meac300-fnade4 firmware
Weakness
CWE-1004
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.