|
PTK contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the HTTPOnly attribute is not set on a cookie, allowing the value to be read or set, allowing a remote attacker to obtain sensitive information via accessing the cookie.
|