Missing 'HttpOnly' Flag in Sensitive Cookie Allows XSS in ABB REX640 PCL1, PCL2, and PCL3 Firmware Modules

Missing 'HttpOnly' Flag in Sensitive Cookie Allows XSS in ABB REX640 PCL1, PCL2, and PCL3 Firmware Modules

CVE-2023-2876 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

Learn more about our Web Application Penetration Testing UK.