Re: [webmin-l] Security scan result: Missing `httpOnly` Cookie Attribute and Missing `secure` Cookie Attribute
Andrey Repin <[email protected]>
| Newsgroups | gmane.comp.web.webmin.general |
|---|---|
| Message-ID | <[email protected]> |
Greetings, Clement Ogedengbe! > The flaw is due to a cookie is not using the 'httpOnly' attribute. This > allows a cookie to be accessed by JavaScript which could lead to session > hijacking attacks. Only if you have installed an untrusted javascript on your webmin host. > Can someone please help with any idea about how to fix this: Working as intended, nothing to fix. -- With best regards, Andrey Repin Thursday, March 14, 2019 4:07:53 Sorry for my terrible english... - Forwarded by the Webmin mailing list at [email protected] To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list