First-Party session cookies are a totally valid use of cookies and actually help improving the security in that a session-id in a cookie will never be copy & pasted by accident (it happens to URL-based session-id's at times) and cookies can be marked as both httponly and secure, making it more difficult to impossible (depending on browser) to XSS the session-id away.
As such I would actually go as far as to prefer a site that requires (first-party session) cookies to one that doesn't.