HIGH🇵🇱 Wersja polska

CVE-2019-20061

CVSS 7.5v3.1pub. 2020-02-10upd. 2024-11-21

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Mfscripts Yetishare

    APP
    Mfscripts
    3.5.2 – 4.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-20062CRITICAL9.8PL ✓same product

MFScripts YetiShare — pominięcie uwierzytelnienia przez wyciek niewygas­ającego tokenu resetu hasła

CVE-2019-19735CRITICAL9.1PL ✓same product

MFScripts YetiShare — słabe hashowanie tokenów resetowania hasła

CVE-2019-20060HIGH7.5same product

MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, t...

CVE-2019-20059HIGH8.8same product

payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly inse...

CVE-2019-19734HIGH8.8same product

_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds pa...