Cookie without HttpOnly flag set

Description

This cookie does not have the HTTPOnly flag set. When a cookie is set with the HTTPOnly flag, it instructs the browser that the cookie can only be accessed by the server and not by client-side scripts. This is an important security protection for session cookies.

Remediation

If possible, you should set the HTTPOnly flag for this cookie.

Severity
Classification
Tags
  • Configuration