PT-2020-10331 · Mfscripts · Mfscripts Yetishare

Published

2020-02-10

·

Updated

2020-02-11

·

CVE-2019-20060

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MFScripts YetiShare versions 3.5.2 through 4.5.4
Description The issue allows sensitive information to be placed in the Referer header. If this information leaks, third parties may discover password-reset hashes, file-delete links, or other sensitive information.
Recommendations For versions 3.5.2 through 4.5.4, consider restricting access to sensitive information and avoid using the Referer header to transmit sensitive data until a fix is available.

Exploit

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20060

Affected Products

Mfscripts Yetishare