Mfscripts records
14 published records for vendor mfscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2019-20062No exploit | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until umfscripts · yetishare · CWE-287 | Critical9.8 | — | 1.6% | Feb 10, 2020 |
36Monitor | CVE-2019-19735No exploit | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micromfscripts · yetishare · CWE-916 | Critical9.1 | — | 0.8% | Dec 30, 2019 |
35Monitor | CVE-2019-19734No exploit | _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.mfscripts · yetishare · CWE-89 | High8.8 | — | 1.1% | Dec 30, 2019 |
35Monitor | CVE-2019-20059Proof of concept | payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 mfscripts · yetishare · CWE-89 | High8.8 | — | 0.9% | Feb 10, 2020 |
35Monitor | CVE-2019-19737No exploit | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requmfscripts · yetishare · CWE-352 | High8.8 | — | 0.5% | Dec 30, 2019 |
30Monitor | CVE-2019-20060No exploit | MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.mfscripts · yetishare · CWE-922 | High7.5 | — | 1.4% | Feb 10, 2020 |
30Monitor | CVE-2019-20061No exploit | The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleamfscripts · yetishare · CWE-319 | High7.5 | — | 0.9% | Feb 10, 2020 |
30Monitor | CVE-2019-19739No exploit | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channmfscripts · yetishare · CWE-311 | High7.5 | — | 0.7% | Dec 30, 2019 |
28Monitor | CVE-2019-19732No exploit | translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSmfscripts · yetishare · CWE-89 | High7.2 | — | 1.1% | Dec 30, 2019 |
24Monitor | CVE-2019-19738No exploit | log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, mfscripts · yetishare · CWE-79 | Medium6.1 | — | 0.7% | Dec 30, 2019 |
24Monitor | CVE-2019-19733No exploit | _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize ormfscripts · yetishare · CWE-79 | Medium6.1 | — | 0.7% | Dec 30, 2019 |
24Monitor | CVE-2019-19736No exploit | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which cmfscripts · yetishare · CWE-732 | Medium6.1 | — | 0.6% | Dec 30, 2019 |
21Monitor | CVE-2019-19805No exploit | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whethermfscripts · yetishare · CWE-203 | Medium5.3 | — | 1.0% | Dec 30, 2019 |
21Monitor | CVE-2019-19806No exploit | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confimfscripts · yetishare · CWE-209 | Medium5.3 | — | 1.0% | Dec 30, 2019 |
- CVE-2019-2006239Monitor
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until u
CriticalCVSS 9.8No exploitEPSS 2%mfscripts · yetishareFeb 10, 2020
- CVE-2019-1973536Monitor
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro
CriticalCVSS 9.1No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1973435Monitor
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.
HighCVSS 8.8No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-2005935Monitor
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0
HighCVSS 8.8Proof of conceptEPSS 1%mfscripts · yetishareFeb 10, 2020
- CVE-2019-1973735Monitor
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requ
HighCVSS 8.8No exploitEPSS 0%mfscripts · yetishareDec 30, 2019
- CVE-2019-2006030Monitor
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.
HighCVSS 7.5No exploitEPSS 1%mfscripts · yetishareFeb 10, 2020
- CVE-2019-2006130Monitor
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in clea
HighCVSS 7.5No exploitEPSS 1%mfscripts · yetishareFeb 10, 2020
- CVE-2019-1973930Monitor
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext chann
HighCVSS 7.5No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1973228Monitor
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aS
HighCVSS 7.2No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1973824Monitor
log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page,
MediumCVSS 6.1No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1973324Monitor
_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or
MediumCVSS 6.1No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1973624Monitor
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which c
MediumCVSS 6.1No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1980521Monitor
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether
MediumCVSS 5.3No exploitEPSS 1%mfscripts · yetishareDec 30, 2019
- CVE-2019-1980621Monitor
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confi
MediumCVSS 5.3No exploitEPSS 1%mfscripts · yetishareDec 30, 2019