MODX Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2014-8775
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.