CVE-2019-16187
09.09.2019, 21:15
Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.Enginsight
Vendor | Product | Version |
---|---|---|
limesurvey | limesurvey | 𝑥 < 3.17.14 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References