CVE-2025-27453
EUVD-2025-1984603.07.2025, 12:15
The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| endress | meac300-fnade4_firmware | 𝑥 ≤ 0.16.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References