Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yetishare CRITICAL 9.8
CVE-2019-20062

MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

Fix: after 4.5.4
Fix from $2,300 2020-02-10
Yetishare HIGH 8.8
CVE-2019-20059

payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter…

Fix: after 4.5.4
Fix from $1,950 2020-02-10
Yetishare HIGH 7.5
CVE-2019-20060

MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password…

Fix: after 4.5.4
Fix from $1,950 2020-02-10
Yetishare HIGH 7.5
CVE-2019-20061

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In…

Fix: after 4.5.4
Fix from $1,950 2020-02-10
Yetishare MEDIUM 5.3
CVE-2019-19805

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email…

Fix: after 4.5.3
Fix from $1,600 2019-12-30
Yetishare MEDIUM 5.3
CVE-2019-19806

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for…

Fix: after 4.5.3
Fix from $1,600 2019-12-30
Yetishare CRITICAL 9.1
CVE-2019-19735

class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), wh…

Fix: after 4.5.3
Fix from $2,300 2019-12-30
Yetishare HIGH 8.8
CVE-2019-19734

_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows …

Fix: after 3.5.2
Fix from $1,950 2019-12-30
Yetishare HIGH 8.8
CVE-2019-19737

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and …

Fix: after 4.5.3
Fix from $1,950 2019-12-30
Yetishare HIGH 7.5
CVE-2019-19739

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.

Fix: after 4.5.3
Fix from $1,950 2019-12-30
Yetishare MEDIUM 6.1
CVE-2019-19736

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potent…

Fix: after 4.5.3
Fix from $1,600 2019-12-30
Yetishare MEDIUM 6.1
CVE-2019-19738

log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, which wou…

Fix: after 4.5.3
Fix from $1,600 2019-12-30
Yetishare HIGH 7.2
CVE-2019-19732

translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 …

Fix: after 4.5.3
Fix from $1,950 2019-12-30
Yetishare MEDIUM 6.1
CVE-2019-19733

_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode t…

Fix: after 4.5.3
Fix from $1,600 2019-12-30