Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
2020-10-29T09:15:13.667
2024-11-21T05:21:36.617
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | synology | router_manager | < 1.2.4-8081 | Yes |