Known Vulnerabilities for Yetishare by Mfscripts
Listed below are 10 of the newest known vulnerabilities associated with "Yetishare" by "Mfscripts".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-20062 json | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never ... | 9.8 - CRITICAL | 2020-02-10 | 2023-11-07 |
| CVE-2019-20061 json | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email ... | 7.5 - HIGH | 2020-02-10 | 2023-11-07 |
| CVE-2019-20060 json | MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parti... | 7.5 - HIGH | 2020-02-10 | 2023-11-07 |
| CVE-2019-20059 json | payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from ... | 8.8 - HIGH | 2020-02-10 | 2023-11-07 |
| CVE-2019-19806 json | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email a... | 5.3 - MEDIUM | 2019-12-30 | 2023-11-07 |
| CVE-2019-19805 json | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depen... | 5.3 - MEDIUM | 2019-12-30 | 2023-11-07 |
| CVE-2019-19739 json | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over ... | 7.5 - HIGH | 2019-12-30 | 2023-11-07 |
| CVE-2019-19738 json | log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile paramete... | 6.1 - MEDIUM | 2019-12-30 | 2023-11-07 |
| CVE-2019-19737 json | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in ... | 8.8 - HIGH | 2019-12-30 | 2023-11-07 |
| CVE-2019-19736 json | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by ... | 6.1 - MEDIUM | 2019-12-30 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mfscripts | Yetishare | 4.5.4 | |||
| Application | Mfscripts | Yetishare | 4.5.3 | |||
| Application | Mfscripts | Yetishare | 4.5.2 | |||
| Application | Mfscripts | Yetishare | 4.5.1 | |||
| Application | Mfscripts | Yetishare | 4.5 | |||
| Application | Mfscripts | Yetishare | 4.4.1 | |||
| Application | Mfscripts | Yetishare | 4.4 | |||
| Application | Mfscripts | Yetishare | 4.3 | |||
| Application | Mfscripts | Yetishare | 4.2 | |||
| Application | Mfscripts | Yetishare | 4.1.1 | |||
| Application | Mfscripts | Yetishare | 4.1 | |||
| Application | Mfscripts | Yetishare | 4.0.1 | |||
| Application | Mfscripts | Yetishare | 4.0 | |||
| Application | Mfscripts | Yetishare | 3.5.3 | |||
| Application | Mfscripts | Yetishare | 3.5.2 | |||
| Application | Mfscripts | Yetishare | 3.5.1 | |||
| Application | Mfscripts | Yetishare | 3.5 | |||
| Application | Mfscripts | Yetishare | 3.4 | |||
| Application | Mfscripts | Yetishare | 3.3 | |||
| Application | Mfscripts | Yetishare | 3.2 |