← Back to CVE List

CVE-2020-27658

Published: 2020-10-29T09:15Z
Last Modified: 2024-11-21T05:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt