PT-2026-53666 · Pinpoint · Pinpoint
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Pinpoint versions prior to 3.1.1
Description
Insecure session management occurs because the
pinpointJwt session cookie lacks HttpOnly and Secure attributes. This allows the cookie to be accessed via JavaScript through document.cookie and transmitted in cleartext over HTTP. Attackers can leverage stored or reflected cross-site scripting to exfiltrate the session token or use network sniffing to intercept it, leading to session hijacking.Recommendations
Update Pinpoint to a version later than 3.1.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pinpoint