2017-03-26, 12:35 AM
When changing your password it updates the mybbuser cookie, but doesn't use the "httponly" parameter like other places do (such as when you login). This results in the mybbuser cookie being able to be accessed from javascript.
![[Image: x1LoCYU.png]](https://camo.mybb.com/96b5dea1d0882c90762402935c40dbfec2b73b6a/68747470733a2f2f692e696d6775722e636f6d2f78314c6f4359552e706e67)
Link to line causing issue.
Link to line causing issue.