Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

Session cookie without 'HttpOnly' Flag in daloRADIUS

Other Research Product
Publication Date:
2022
abstract:
The article provides technical details on a security issue discovered in daloRADIUS (https://github.com/lirantal/daloradius), along with the patch to apply for correcting the issue. In particular, all versions of daloRADIUS prior to the master branch transmit the session cookie (i.e. PHPSESSID) without setting the HttpOnly flag. The problem could cause JavaScript (e.g., using document.cookies) to access the PHPSESSID cookie value on the browser side.
Iris type:
05.12 Altro
Keywords:
cybersecurity; vulnerability; disclosure; cve; patch
List of contributors:
Lauria, FILIPPO MARIA
Authors of the University:
LAURIA FILIPPO MARIA
Handle:
https://iris.cnr.it/handle/20.500.14243/416328
  • Overview

Overview

URL

https://huntr.dev/bounties/401661ee-40e6-4ee3-a925-3716b96ece5c/
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)