HumHub is an Open Source Enterprise Social Network. Easy to install, intuitive to use and extendable with countless freely available modules.
6.32k
stars
1.66k
forks
source link
Insecure cookie setting: missing Secure flag. #5332
Closed
samuk closed 1 year ago
What steps will reproduce the problem?
Run a pentest against community.humhub.com or other Humhub instance
What is the expected result?
Cookies have the secure flag set
What do you get instead?
A cookie has an insecure flag set.
Additional info
Full pentest report is available here: https://community.humhub.com/file/file/download?guid=655c1e62-f718-404a-8148-34517a465027&hash_sha1=84bd903a