inside the generated script element. Mitigation base64-encodes th","datePublished":"2026-04-22T19:28:08.720000+00:00","dateModified":"2026-06-10T18:58:07.798000+00:00","inLanguage":"pt","author":{"@type":"Organization","name":"Vexday"},"publisher":{"@type":"Organization","name":"Vexday","url":"https://vexday.io"},"mainEntityOfPage":"https://vexday.io/pt/cve/CVE-2026-6019","keywords":"CVE-2026-6019, CWE-150","breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Início","item":"https://vexday.io/pt"},{"@type":"ListItem","position":2,"name":"CVE-2026-6019"}]}}← voltar
CVE-2026-6019

BaseCookie.js_output() does not neutralize embedded characters

CVSS 2.1 LOWEPSS 0.2%CWE-150
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →