adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
References
Link | Resource |
---|---|
https://github.com/pi-hole/adminlte/commit/cf8602eedd4a31eadb72372fc878c12d342f8600 | Patch Third Party Advisory |
https://huntr.dev/bounties/ac7fd77b-b31b-4d02-aebd-f89ecbae3fce | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
Information
Published : 2021-09-15 00:15
Updated : 2022-10-25 11:30
NVD link : CVE-2021-3706
Mitre link : CVE-2021-3706
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
pi-hole
- web_interface