Sensitive Cookie Without 'HttpOnly' Flag in Wekan - #VU146569
Published: September 1, 2026 / Updated: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the "meteor_login_token" session-authentication cookie is set without the HttpOnly attribute. A remote attacker can exploit an XSS vulnerability to steal the session authentication cookie, leading to session hijacking and account takeover.