← back
CVE-2019-19003

ABB eSOMS: HTTPOnly flag not set

CVSS 5.3 MEDIUMEPSS 0.8%CWE-16CWE-79
For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
ABB · eSOMS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →