ZeroHour

CVE-2019-19736

CVSS 3.1
6.1 medium
EPSS
<1%p47
Published
()
Modified
Description

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.

Vendors
mfscripts
Products
yetishare
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.