PT-2019-15967 · Mfscripts · Mfscripts Yetishare

Published

2019-12-30

·

Updated

2021-07-21

·

CVE-2019-19806

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MFScripts YetiShare versions 3.5.2 through 4.5.3
Description The issue allows an attacker to enumerate accounts by guessing email addresses, as the account forgot password.ajax.php file displays a message indicating whether an email address is configured for the provided account name.
Recommendations For versions 3.5.2 through 4.5.3, consider modifying the account forgot password.ajax.php file to not disclose whether an email address is configured for the account name, or restrict access to this file to prevent account enumeration.

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19806

Affected Products

Mfscripts Yetishare