CVE-2019-19736

MEDIUM

MFScripts YetiShare <4.5.3 - XSS

Title source: llm
STIX 2.1

Description

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0027
EPSS Percentile 50.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-732
Status published
Products (1)
mfscripts/yetishare 3.5.2 - 4.5.3
Published Dec 30, 2019
Tracked Since Feb 18, 2026