Skip to content
Noroxi

Mfscripts records

14 published records for vendor mfscripts.

All records

14 records
  • MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until u

    CriticalCVSS 9.8No exploitEPSS 2%

    mfscripts · yetishareFeb 10, 2020

  • class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro

    CriticalCVSS 9.1No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string.

    HighCVSS 8.8No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0

    HighCVSS 8.8Proof of conceptEPSS 1%

    mfscripts · yetishareFeb 10, 2020

  • MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requ

    HighCVSS 8.8No exploitEPSS 0%

    mfscripts · yetishareDec 30, 2019

  • MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header.

    HighCVSS 7.5No exploitEPSS 1%

    mfscripts · yetishareFeb 10, 2020

  • The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in clea

    HighCVSS 7.5No exploitEPSS 1%

    mfscripts · yetishareFeb 10, 2020

  • MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext chann

    HighCVSS 7.5No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aS

    HighCVSS 7.2No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page,

    MediumCVSS 6.1No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or

    MediumCVSS 6.1No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which c

    MediumCVSS 6.1No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether

    MediumCVSS 5.3No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019

  • _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is confi

    MediumCVSS 5.3No exploitEPSS 1%

    mfscripts · yetishareDec 30, 2019