CVE-2019-19739

HIGH

Mfscripts Yetishare < 4.5.3 - Missing Encryption

Title source: rule
STIX 2.1

Description

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.

Scores

CVSS v3 7.5
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-311
Status published
Products (1)
mfscripts/yetishare 3.5.2 - 4.5.3
Published Dec 30, 2019
Tracked Since Feb 18, 2026