CVE-2025-49189: Cookie missing HttpOnly flag
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49189?
The severity of CVE-2025-49189 is categorized as medium with a score of 6.1.
What is the risk associated with CVE-2025-49189?
The risk associated with CVE-2025-49189 includes increased vulnerability to Cross-Site Scripting (XSS) attacks due to the Cookie missing the HttpOnly flag.
How do I fix CVE-2025-49189?
To fix CVE-2025-49189, it is recommended to upgrade to the latest release of SICK Media Server (version 1.5 or higher).
What vulnerabilities does CVE-2025-49189 expose?
CVE-2025-49189 exposes the application to potential Cross-Site Scripting (XSS) attacks targeting the stored cookies.
What software is affected by CVE-2025-49189?
CVE-2025-49189 affects the SICK Media Server software.