|
Aklacon OpenCMS contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the HTTPOnly attribute is not set on multiple cookies, allowing the value to be read or set, allowing a remote attacker to obtain sensitive information via accessing the cookie.
|