Description
Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.
Remediation
References
Related Vulnerabilities
WordPress Plugin Eu Cookie Notice Cross-Site Request Forgery (1.0.6)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-8109)
MySQL CVE-2019-2774 Vulnerability (CVE-2019-2774)
Oracle JRE CVE-2013-5777 Vulnerability (CVE-2013-5777)
Internet Information Services Other Vulnerability (CVE-2000-0951)