The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NMfscripts Yetishare
APPMfscripts3.5.2 – 4.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-20062CRITICAL9.8PL ✓same product
MFScripts YetiShare — pominięcie uwierzytelnienia przez wyciek niewygasającego tokenu resetu hasła
CVE-2019-19735CRITICAL9.1PL ✓same product
MFScripts YetiShare — słabe hashowanie tokenów resetowania hasła
CVE-2019-20060HIGH7.5same product
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, t...
CVE-2019-20059HIGH8.8same product
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly inse...
CVE-2019-19734HIGH8.8same product
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds pa...