The second issue I am seeing after fresh install of limesurvey on ubuntu 18.04 and Apache2 is: Non-HttpOnly Session Cookies Identified.
Specifically:
The website software running on this server appears to be setting session
cookies without the HttpOnly flag set. This means the session identifier
information in these cookies is susceptible to attacks such as Cross-site Scripting
which may allow attackers to read this cookie's data.
Can you report the issue ? Then we made it by default (i don't see why we don't made it currently)
Assistance on LimeSurvey forum and LimeSurvey core development are on my free time.
I'm not a LimeSurvey GmbH member. -
Professional support
-
Plugins, theme and development
. I don't answer to private message.