F042. Insecurely generated cookies


The application’s cookies are generated without properly setting the HttpOnly, Secure and SameSite attributes. This could enable an attacker to compromise a user’s session through XSS, sniffing or CSRF attacks.

