Why isn’t the PHPSESSID cookie HttpOnly?
And why if the XSS was already known had they not fixed it?!
Not marking the cookie httpOnly ironically doesn't surprise me.
TLDR: if you aren't going to look up the very basics of security just use a trusted library
Why isn’t the PHPSESSID cookie HttpOnly?
And why if the XSS was already known had they not fixed it?!