Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pinpoint-apm
Pinpoint-apm pinpoint |
|
| CPEs | cpe:2.3:a:pinpoint-apm:pinpoint:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pinpoint
Pinpoint pinpoint Booking System |
Pinpoint-apm
Pinpoint-apm pinpoint |
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking. | |
| Title | Pinpoint - Insecure Session Cookie Attributes in pinpointJwt | |
| First Time appeared |
Pinpoint
Pinpoint pinpoint Booking System |
|
| Weaknesses | CWE-1004 CWE-614 |
|
| CPEs | cpe:2.3:a:pinpoint:pinpoint_booking_system:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Pinpoint
Pinpoint pinpoint Booking System |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-29T17:19:11.989Z
Updated: 2026-06-30T13:58:23.552Z
Reserved: 2026-06-26T13:57:16.356Z
Link: CVE-2026-57948
Updated: 2026-06-30T13:57:54.897Z
No data.
No data.