Description
Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.
Remediation
References
Related Vulnerabilities
WordPress Plugin Feature Slideshow 'src' Parameter Cross-Site Scripting (1.0.6beta)
Oracle Database Server CVE-2006-1874 Vulnerability (CVE-2006-1874)
WordPress Plugin Simple:Press-WordPress Forum Arbitrary File Upload (6.6.0)
WordPress Plugin SVG Support Cross-Site Scripting (2.5.1)
WordPress Plugin Vertical SlideShow 'upload.php' Arbitrary File Upload (2.1)