MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
                
            References
                    | Link | Resource | 
|---|---|
| https://medium.com/@jra8908/yetishare-3-5-2-4-5-3-multiple-vulnerabilities-2d01d0cd7459 | Third Party Advisory | 
Configurations
                    Information
                Published : 2019-12-30 09:15
Updated : 2020-01-07 12:28
NVD link : CVE-2019-19736
Mitre link : CVE-2019-19736
JSON object : View
CWE
                
                    
                        
                        CWE-732
                        
            Incorrect Permission Assignment for Critical Resource
Products Affected
                mfscripts
- yetishare


