Description
Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.
Remediation
References
Related Vulnerabilities
Atlassian Confluence Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2928)
WordPress Plugin Gallery-Photo Albums-Portfolio Cross-Site Scripting (1.3.47)
WordPress Plugin myLinksDump 'url' Parameter SQL Injection (1.2)
WordPress Plugin Share Buttons by AddThis Cross-Site Request Forgery (5.3.5)