CVE Database · CVE-2013-4617
CVSS v3.1
N/A
EPSS
1.26%
Published
Nov 27, 2013
Modified
Apr 28, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Weaknesses (CWE)
Affected Products (1)
References (2)