-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Normal
-
Affects Version/s: None
-
Component/s: None
-
None
The remember_login should not be accessible to JavaScript and is prone to XSS attacks otherwise.
Set the remember_login cookie to HttpOnly to forbid that from happening.