MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
References
Link | Resource |
---|---|
https://medium.com/@jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459 | Third Party Advisory |
Configurations
Information
Published : 2019-12-30 09:15
Updated : 2020-01-07 12:28
NVD link : CVE-2019-19736
Mitre link : CVE-2019-19736
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
mfscripts
- yetishare