-
Notifications
You must be signed in to change notification settings - Fork 115
SEC: Access Token Misconfiguration — insecure cookie flags #188
Copy link
Copy link
Closed
Labels
complexity-lowComplexity: low (board points 1-3)Complexity: low (board points 1-3)pentestFrom penetration testing reportFrom penetration testing reportpriority-p2ImportantImportantsecuritySecurity vulnerabilitySecurity vulnerabilityseverity-lowLow severity security findingLow severity security findingtheme-securityTheme: SecurityTheme: Security
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
complexity-lowComplexity: low (board points 1-3)Complexity: low (board points 1-3)pentestFrom penetration testing reportFrom penetration testing reportpriority-p2ImportantImportantsecuritySecurity vulnerabilitySecurity vulnerabilityseverity-lowLow severity security findingLow severity security findingtheme-securityTheme: SecurityTheme: Security
Pentest Finding 3.3.5 — Low (CVSS 2.0)
Location: Frontend cookie handling at
http://localhost/Impact
The application mirrors the Local Storage authentication token into a cookie without
SecureorHttpOnlyflags:Secure— browser transmits the token in plaintext over HTTP, enabling MitM session hijack on public Wi-FiHttpOnly— token accessible viadocument.cookie, expanding XSS attack surfaceWhile the app logic uses Local Storage for API communication, browsers automatically attach cookies to outbound requests, creating a secondary extraction vector.
Remediation
Secure,HttpOnly, andSameSiteattributesReferences
Source: UnderDefense Web Pentest Report, March 2026