Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 30 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pinpoint-apm
Pinpoint-apm pinpoint |
|
| CPEs | cpe:2.3:a:pinpoint-apm:pinpoint:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pinpoint
Pinpoint pinpoint Booking System |
Pinpoint-apm
Pinpoint-apm pinpoint |
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking. | |
| Title | Pinpoint - Insecure Session Cookie Attributes in pinpointJwt | |
| First Time appeared |
Pinpoint
Pinpoint pinpoint Booking System |
|
| Weaknesses | CWE-1004 CWE-614 |
|
| CPEs | cpe:2.3:a:pinpoint:pinpoint_booking_system:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Pinpoint
Pinpoint pinpoint Booking System |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-30T13:58:23.552Z
Reserved: 2026-06-26T13:57:16.356Z
Link: CVE-2026-57948
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T20:00:03Z