Description
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
Remediation
References
Related Vulnerabilities
OpenSSL Improper Certificate Validation Vulnerability (CVE-2019-1552)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3394)
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.5.3)
WordPress Plugin String locator PHAR Deserialization (2.5.0)
Oracle Application Server Other Vulnerability (CVE-2002-0659)