Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking. | |
| Title | Pinpoint - Insecure Session Cookie Attributes in pinpointJwt | |
| First Time appeared |
Pinpoint
Pinpoint pinpoint Booking System |
|
| Weaknesses | CWE-1004 CWE-614 |
|
| CPEs | cpe:2.3:a:pinpoint:pinpoint_booking_system:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Pinpoint
Pinpoint pinpoint Booking System |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-29T17:19:11.989Z
Reserved: 2026-06-26T13:57:16.356Z
Link: CVE-2026-57948
No data.
No data.
No data.
OpenCVE Enrichment
No data.