MyBB Community Forums

Full Version: mybbuser cookie is set without httponly when changing password
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
When changing your password it updates the mybbuser cookie, but doesn't use the "httponly" parameter like other places do (such as when you login). This results in the mybbuser cookie being able to be accessed from javascript.
[Image: x1LoCYU.png]
Link to line causing issue.
Hi,

Thank you for your report. We have pushed this issue to our Github repository for further analysis where you can track our commits and progress with fixing this bug. Discussions regarding this bug may also take place there too.

Follow this link to visit the issue on Github: https://github.com/mybb/mybb/issues/2705

Thanks for contributing to MyBB!

Regards,
The MyBB Group