HIGH🇵🇱 Wersja polska

CVE-2019-19734

CVSS 8.8v3.1pub. 2019-12-30upd. 2024-11-21

_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Mfscripts Yetishare

    APP
    Mfscripts
    ≤ 3.5.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2019-20062CRITICAL9.8PL ✓same product

MFScripts YetiShare — pominięcie uwierzytelnienia przez wyciek niewygas­ającego tokenu resetu hasła

CVE-2019-19735CRITICAL9.1PL ✓same product

MFScripts YetiShare — słabe hashowanie tokenów resetowania hasła

CVE-2019-20059HIGH8.8same product

payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly inse...

CVE-2019-20060HIGH7.5same product

MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, t...

CVE-2019-20061HIGH7.5same product

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password...