ZeroHour

CVE-2019-20061

CVSS 3.1
7.5 high
EPSS
<1%p58
Published
()
Modified
Description

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.

Vendors
mfscripts
Products
yetishare
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.