Potential Vulnerability for BirdNetPi PHPSESSID Cookie #1188
Fryerchristopher
started this conversation in
General
Replies: 1 comment 2 replies
-
Bump. Can anyone recommend a way to add the httponly and secure flags to the PHPSESSID cookie? Thank you. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I did a free scan of my BirdNetPI that I have made public (for my own use and not advertised but open to all) and it found two issues with the PHPSESSID cookie. Specifically, the scan recommends adding the httponly and secure flags to the cookie. Has anyone done this or do you know how? The cookie is in views.php I think. I am not much of a programmer so while I can find references for how to do this on the web, I don't want to break the website. I used https://pentest-tools.com/website-vulnerability-scanning for the test.
Beta Was this translation helpful? Give feedback.
All reactions