Mfscripts / Yetishare
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-20060 | MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset has… | HIGH | 7.5 | Feb 10, 2020 |
| CVE-2019-20061 | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other wor… | HIGH | 7.5 | Feb 10, 2020 |
| CVE-2019-20062 | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). | CRITICAL | 9.8 | Feb 10, 2020 |
| CVE-2019-20059 | payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQ… | HIGH | 8.8 | Feb 10, 2020 |
| CVE-2019-19806 | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the accou… | MEDIUM | 5.3 | Dec 30, 2019 |
| CVE-2019-19805 | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address i… | MEDIUM | 5.3 | Dec 30, 2019 |
| CVE-2019-19738 | log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, which would allow a… | MEDIUM | 6.1 | Dec 30, 2019 |
| CVE-2019-19737 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentiall… | HIGH | 8.8 | Dec 30, 2019 |
| CVE-2019-19736 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be u… | MEDIUM | 6.1 | Dec 30, 2019 |
| CVE-2019-19735 | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows… | CRITICAL | 9.1 | Dec 30, 2019 |
| CVE-2019-19734 | _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacke… | HIGH | 8.8 | Dec 30, 2019 |
| CVE-2019-19733 | _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output… | MEDIUM | 6.1 | Dec 30, 2019 |
| CVE-2019-19732 | translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSo… | HIGH | 7.2 | Dec 30, 2019 |
| CVE-2019-19739 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels. | HIGH | 7.5 | Dec 30, 2019 |
Showing 1 to 14 of 14 CVEs