{"api_version":"1","generated_at":"2026-07-23T10:27:45+00:00","cve":"CVE-2019-19736","urls":{"html":"https://cve.report/CVE-2019-19736","api":"https://cve.report/api/cve/CVE-2019-19736.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-19736","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-19736"},"summary":{"title":"CVE-2019-19736","description":"MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-12-30 17:15:00","updated_at":"2023-11-07 03:07:00"},"problem_types":["CWE-732"],"metrics":[],"references":[{"url":"https://medium.com/@jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459","name":"https://medium.com/@jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459","refsource":"MISC","tags":["Third Party Advisory"],"title":"YetiShare 3.5.2–4.5.3, Multiple vulnerabilities | by Jinny Ramsmark | Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/%40jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459","name":"https://medium.com/%40jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459","refsource":"","tags":[],"title":"YetiShare 3.5.2–4.5.3, Multiple vulnerabilities | by Jinny Ramsmark | Medium","mime":"text/html","httpstatus":"410","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-19736","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19736","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"19736","vulnerable":"1","versionEndIncluding":"4.5.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mfscripts","cpe5":"yetishare","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-19736","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://medium.com/@jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459","url":"https://medium.com/@jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459"}]}},"nvd":{"publishedDate":"2019-12-30 17:15:00","lastModifiedDate":"2023-11-07 03:07:00","problem_types":["CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mfscripts:yetishare:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.2","versionEndIncluding":"4.5.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"19736","Ordinal":"162731","Title":"CVE-2019-19736","CVE":"CVE-2019-19736","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"19736","Ordinal":"1","NoteData":"MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"19736","Ordinal":"2","NoteData":"2019-12-30","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"19736","Ordinal":"3","NoteData":"2019-12-30","Type":"Other","Title":"Modified"}]}}}