Skip to main content

Threats Tagged 'cwe-1004'

View all threats tagged with 'cwe-1004'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1004

Threats Tagged 'cwe-1004'

Click on any threat for detailed analysis and mitigation recommendations

Open Access Management (OpenAM) prior to version 16.1.1 has a vulnerability where the default configuration sets the iPlanetDirectoryPro SSO cookie without HttpOnly and SameSite protections. This cookie is reused as a CSRF token in OAuth and OpenID Connect consent flows. Combined with same-origin cross-site scripting and user interaction with attacker-controlled links, this can lead to theft of the SSO session and unauthorized consent grants. The issue is fixed in version 16.1.1.

Join the discussion

HCL Software Hive version 1.0 contains a vulnerability where sensitive cookies are set without the 'HttpOnly' flag. This issue is part of multiple infrastructure and network configuration vulnerabilities that could allow unauthorized lateral movement, container breakout, and exposure of sensitive data within internal communications. The vulnerability has a CVSS score of 5.4, indicating a medium severity level.

Join the discussion

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it within the browser's DOM. Although the application ultimately returns an HTTP 500 error due to the malformed API request caused by the payload, the browser's JavaScript engine parses and executes the injected <script> tags before the error response is returned — resulting in successful code execution regardless of the server-side error. This vulnerability is fixed in 7.1.0.

Join the discussion

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator views the page. This enables attackers to steal the administrator’s session cookies, potentially leading to full administrative account takeover. This vulnerability is fixed in 6.5.3.

Join the discussion

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values.

Join the discussion

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an insecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information and gain unau-thorized access to the targeted device.

Join the discussion

HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Join the discussion

CVE-2025-42909 is a low-severity vulnerability in SAP Cloud Appliance Library Appliances, specifically affecting the TITANIUM_WEBAPP 4.0 version. It involves a sensitive cookie lacking the HttpOnly flag due to an insecure default profile setting in S/4HANA appliances. An attacker with high privileges on one appliance could potentially access other appliances by exploiting this cookie vulnerability. The impact on confidentiality is low, and there is no impact on integrity or availability. Exploitation requires network access, high privileges, and no user interaction. No known exploits are currently reported in the wild. European organizations using SAP CAL appliances should review and harden their cookie security settings to mitigate risk. Countries with significant SAP enterprise deployments and critical infrastructure relying on SAP systems are more likely to be affected.

Join the discussion

This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A remote attacker could exploit this vulnerability by capturing the session cookies transmitted over an unsecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information from the targeted device.

Join the discussion

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: cwe-1004
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses