teerth04 / opencart

Other
0 stars 0 forks source link

SameSite Cookie Not Implemented #65

Open armorcodegithubqa[bot] opened 1 year ago

armorcodegithubqa[bot] commented 1 year ago

Cookies are typically sent to third parties in cross origin requests. This can be abused to do CSRF attacks. Recently a new cookie attribute named SameSite was proposed to disable third-party usage for some cookies, to prevent CSRF attacks.

Same-site cookies allow servers to mitigate the risk of CSRF and information leakage attacks by asserting that a particular cookie should only be sent with requests initiated from the same registrable domain.

Finding Id : [38248270|https://qa.armorcode.ai/#/findings/278/1413/38248270]