Cookie Management Flaw in Znuny Affects Versions Up to 7.1.3
CVE-2025-26844
9.8CRITICAL
What is CVE-2025-26844?
An issue has been identified in Znuny prior to version 7.1.3 that involves a cookie being set without the HttpOnly flag. This misconfiguration can allow for potential cross-site scripting (XSS) attacks, where an attacker may exploit the lack of this security measure. Implementing the HttpOnly flag is crucial as it prevents client-side scripts from accessing the cookie data, thereby enhancing the security posture. Users of affected versions are advised to review their cookie settings and apply necessary updates.
